Posting Date: 2026/09/04
【Vulnerability Alert】Multiple High-Risk Security Vulnerabilities in Splunk Enterprise, Please Verify and Patch Immediately
- Subject: 【Vulnerability Alert】Multiple High-Risk Security Vulnerabilities in Splunk Enterprise, Please Verify and Patch Immediately
- Description:
- Forwarded Security Alert from National Information Security Sharing and Analysis Center (NISAC) Alert ID: NISAC-200-202609-00000006
- Researchers have discovered multiple high-risk security vulnerabilities in Splunk Enterprise (CVE-2026-76253, CVE-2026-76310 through CVE-2026-76317, CVE-2026-76319, CVE-2026-76335, and CVE-2026-76350 through CVE-2026-76352). Among them, the most severe is CVE-2026-76310, an Improper Access Control vulnerability. An unauthenticated remote attacker holding an embedded report token can download dispatch archives for associated search jobs and extract session-related information, thereby gaining access to data accessible by the report owner and compromising system integrity. If the report owner possesses the admin role, the attacker could even execute administrative operations. Please verify and apply patches as soon as possible.
- Affected Systems:
- Splunk Enterprise versions 9.4.0 to 9.4.13, 10.0.0 to 10.0.8, 10.2.0 to 10.2.5, and 10.4.0 to 10.4.1
- Recommendations:
- The vendor has released security patches for these vulnerabilities. Please upgrade Splunk Enterprise to version 9.4.14, 10.0.9, 10.2.6, or 10.4.2 or later. For detailed information, please refer to the official advisory at: https://advisory.splunk.com/advisories/SVD-2026-0801
- References:
Computer and Communication Center
Network System Division