LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-76354

splunk · splunk

Published
CVSS8.1
Severityhigh
WeaknessCWE-158
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API request that deletes or temporarily overwrites files writable by the user account running Splunk Enterprise processes on a non-captain search head cluster member. The vulnerability is possible because Search Head Clustering bundle replication does not validate the name of a replicated bundle file or neutralize NUL bytes before constructing the member bundle path. For more information see About search head clustering (https://help.splunk.com/en/splunk-e

References

← Back to the CVE Tracker

Our coverage of CVE-2026-76354

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-76354.