Denial of Service Vulnerability in Splunk Enterprise by Splunk
CVE-2026-76271
6.5MEDIUM
What is CVE-2026-76271?
A vulnerability exists in versions of Splunk Enterprise prior to 10.4.3, 10.2.7, and 10.0.10, where a low-privileged user could exploit an inefficient regular expression used in the input validation of a REST API endpoint within the Discover Splunk Observability Cloud app. This could lead to a denial of service condition. It is crucial for users to upgrade to the latest versions to mitigate the risk associated with this vulnerability.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.3
Splunk Enterprise 10.2 < 10.2.7
Splunk Enterprise 10.0 < 10.0.10