Unauthorized Module Deletion in Splunk Enterprise Affects System Integrity
CVE-2026-76336
7.1HIGH
What is CVE-2026-76336?
In Splunk Enterprise versions prior to 10.4.2 and 10.2.6, a vulnerability exists that enables any user, without appropriate roles, to delete all Search Processing Language 2 (SPL2) modules via the SPL2 module management REST API. This flaw occurs due to insufficient authorization checks, which may lead to the deletion of essential datasets and functions, jeopardizing system integrity and potentially causing partial service disruptions. Users should refer to official Splunk documentation for guidance on module management and permissions.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6