Username Validation Flaw in Splunk Enterprise from Splunk
CVE-2026-76277

4.1MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
7 October 2026

What is CVE-2026-76277?

In specific versions of Splunk Enterprise, a flaw in username validation allows users with edit_user capabilities to create usernames that erroneously end with a period. This misconfiguration may lead to overlapping user configurations, resulting in incorrect user management and potential data leaks. Administrators should review roles and authentication setups to mitigate this risk and ensure proper isolation of user data.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.3

Splunk Enterprise 10.2 < 10.2.7

Splunk Enterprise 10.0 < 10.0.10

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.