CVE-2026-76317CWE-26

CVE-2026-76317

High · published August 20, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
31.7
In the wild
Unconfirmed
What it is

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could move files that the user account running Splunk Enterprise can read into a lookup that the user controls. The user could then access all relevant data and affect system integrity and availability on the search head. The vulnerability is possible because the lookup configuration endpoint does not resolve lookup source paths before checking whether they stay inside the allowed lookup staging area. For more information see About lookups (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/10.4/use-lookups-in-splunk-web/about-lookups) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00386 · 31.7th percentile
Weakness
CWE-26 · Path Traversal: '/dir/../filename'
Published
2026-08-20T02:17Z
Affected products (4)
ProductVersionsFixed in
splunk/splunk≥ 9.4.0, < 9.4.149.4.14
splunk/splunk≥ 10.0.0, < 10.0.910.0.9
splunk/splunk≥ 10.2.0, < 10.2.610.2.6
splunk/splunk≥ 10.4.0, < 10.4.210.4.2
References (1)
EPSS history
Timeline
  • 19 AUG 21:34Z
    Path Traversal through the Lookup Configuration REST API in Splunk Enterprise
    cvelistv5