Directory traversal vulnerability in Splunk Enterprise by Splunk
CVE-2026-76279
4.3MEDIUM
What is CVE-2026-76279?
In certain versions of Splunk Enterprise, a flaw allows users with specific roles to bypass index access restrictions by manipulating whitespace in index names. This oversight enables unauthorized users to write to internal indexes, potentially compromising sensitive data integrity.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.3
Splunk Enterprise 10.2 < 10.2.7
Splunk Enterprise 10.0 < 10.0.10