Directory Traversal Vulnerability in Splunk Enterprise by Splunk
CVE-2026-76344
7.7HIGH
What is CVE-2026-76344?
A directory traversal vulnerability exists in Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. This issue allows unauthorized users, lacking 'admin' or 'power' roles, to write dispatch metadata to arbitrary locations on the host system through a crafted search identifier sent to a REST API endpoint. The lack of validation for the search identifier enables potential manipulation that could compromise system integrity. For more details, refer to the official advisory by Splunk.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9