Username Validation Flaw in Splunk Enterprise from Splunk
CVE-2026-76277
4.1MEDIUM
What is CVE-2026-76277?
In specific versions of Splunk Enterprise, a flaw in username validation allows users with edit_user capabilities to create usernames that erroneously end with a period. This misconfiguration may lead to overlapping user configurations, resulting in incorrect user management and potential data leaks. Administrators should review roles and authentication setups to mitigate this risk and ensure proper isolation of user data.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.3
Splunk Enterprise 10.2 < 10.2.7
Splunk Enterprise 10.0 < 10.0.10