Local Command Execution Vulnerability in Splunk Enterprise for Linux
CVE-2026-76266

7.7HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
7 October 2026

What is CVE-2026-76266?

Inversions of Splunk Enterprise prior to 10.4.3 on Linux allow local users to execute arbitrary commands with root privileges during package upgrades. This occurs when the maintainer script of the Linux package improperly trusts the existing Splunk installation, enabling a local user to modify installation content before an upgrade. As a result, attackers could exploit this vulnerability to gain unauthorized system access through escalated privileges.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.3

Splunk Enterprise 10.2 < 10.2.7

Splunk Enterprise 10.0 < 10.0.10

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jean-Michel Remi Boudreau
.