CVE-2026-76344CWE-27

CVE-2026-76344

High · published August 20, 2026

CVSS v3.1
7.7
EPSS
0%
Percentile
21.8
In the wild
Unconfirmed
What it is

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Representational State Transfer (REST) API endpoint and affect system integrity on the host. The vulnerability is possible because Splunk Enterprise does not validate the search identifier before using it to create a dispatch directory. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

The record
Technical detail
CVSS v3.1
7.7 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00296 · 21.8th percentile
Weakness
CWE-27 · Path Traversal: 'dir/../../filename'
Published
2026-08-20T02:17Z
Affected products (4)
ProductVersionsFixed in
splunk/splunk≥ 9.4.0, < 9.4.149.4.14
splunk/splunk≥ 10.0.0, < 10.0.910.0.9
splunk/splunk≥ 10.2.0, < 10.2.610.2.6
splunk/splunk≥ 10.4.0, < 10.4.210.4.2
References (1)
EPSS history
Timeline
  • 19 AUG 21:34Z
    Path Traversal through the Search Dispatch REST API in Splunk Enterprise
    cvelistv5