Improper Access Control in Splunk Enterprise by Splunk
CVE-2026-76281

Currently unrated

Key Information:

Vendor

Splunk

Vendor
CVE Published:
7 October 2026

What is CVE-2026-76281?

Splunk Enterprise has encountered an improper access control vulnerability that could potentially allow unauthorized users to access sensitive information or perform actions beyond their permissions. The issue has been identified across multiple versions of Splunk Enterprise, including 10.4.3, 10.2.7, 10.0.10, and 9.4.15. Users are advised to review the advisory provided by Splunk for further details on mitigation and to ensure their systems are updated to the latest versions to withstand potential exploit attempts.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.3

Splunk Enterprise 10.2 < 10.2.7

Splunk Enterprise 10.0 < 10.0.10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.