CVE-2026-76353CWE-24

CVE-2026-76353

Medium · published August 20, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
20.5
In the wild
Unconfirmed
What it is

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager. This could affect system integrity and disrupt service. The vulnerability is possible because knowledge bundle delta processing does not restrict removal paths to the staging directory and the endpoint does not enforce the expected authorization boundary. For more information see Knowledge bundle replication overview (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/knowledge-bundle-replication/knowledge-bundle-replication-overview) in the Splunk documentation.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00283 · 20.5th percentile
Weakness
CWE-24 · Path Traversal: '../filedir'
Published
2026-08-20T02:17Z
Affected products (4)
ProductVersionsFixed in
splunk/splunk≥ 9.4.0, < 9.4.149.4.14
splunk/splunk≥ 10.0.0, < 10.0.910.0.9
splunk/splunk≥ 10.2.0, < 10.2.610.2.6
splunk/splunk≥ 10.4.0, < 10.4.210.4.2
References (1)
EPSS history
Timeline
  • 19 AUG 21:34Z
    Path Traversal through Knowledge Bundle Replication in Splunk Enterprise
    cvelistv5