Unauthorized Module Deletion in Splunk Enterprise Affects System Integrity
CVE-2026-76336

7.1HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76336?

In Splunk Enterprise versions prior to 10.4.2 and 10.2.6, a vulnerability exists that enables any user, without appropriate roles, to delete all Search Processing Language 2 (SPL2) modules via the SPL2 module management REST API. This flaw occurs due to insufficient authorization checks, which may lead to the deletion of essential datasets and functions, jeopardizing system integrity and potentially causing partial service disruptions. Users should refer to official Splunk documentation for guidance on module management and permissions.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.