Forwarded from National Information Sharing and Analysis Center Cybersecurity Information Alert NISAC-200-202609-00000006
[Content Description]
Researchers discovered that Splunk Enterprise contains multiple high-risk security vulnerabilities(CVE-2026-76253、CVE-2026-76310 to CVE-2026-76317、CVE-2026-76319、CVE-2026-76335 and CVE-2026-76350 to CVE-2026-76352). Among them, the most severe, CVE-2026-76310, is an Improper Access Control vulnerability. If an unauthenticated remote attacker possesses an embedded report token(Token), they can download the dispatch archive of the relevant search job and obtain session-related information from it, thereby accessing data accessible to the report owner and affecting system integrity. If the report owner has the admin role, the attacker may even perform administrative operations. Please confirm and patch as soon as possible.
[Affected Platforms]
Splunk Enterprise versions 9.4.0 to 9.4.13、10.0.0 to 10.0.8、10.2.0 to 10.2.5 and 10.4.0 to 10.4.1
[Recommended Measures]
The official source has released patches for the vulnerabilities. Please upgrade Splunk Enterprise to version 9.4.14、10.0.9、10.26 or 10.4.2(inclusive) or later versions. For detailed information, please refer to the official advisory at the following URL: https://advisory.splunk.com/advisories/SVD-2026-0801
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-76253
2. https://nvd.nist.gov/vuln/detail/CVE-2026-76310
3. https://nvd.nist.gov/vuln/detail/CVE-2026-76311
4. https://nvd.nist.gov/vuln/detail/CVE-2026-76312
5. https://nvd.nist.gov/vuln/detail/CVE-2026-76313
6. https://nvd.nist.gov/vuln/detail/CVE-2026-76314
7. https://nvd.nist.gov/vuln/detail/CVE-2026-76315
8. https://nvd.nist.gov/vuln/detail/CVE-2026-76316
9. https://nvd.nist.gov/vuln/detail/CVE-2026-76317
10. https://nvd.nist.gov/vuln/detail/CVE-2026-76319
11. https://nvd.nist.gov/vuln/detail/CVE-2026-76335
12. https://nvd.nist.gov/vuln/detail/CVE-2026-76350
13. https://nvd.nist.gov/vuln/detail/CVE-2026-76351
14. https://nvd.nist.gov/vuln/detail/CVE-2026-76352
15. https://advisory.splunk.com/advisories/SVD-2026-0801