Directory Traversal Vulnerability in Splunk Enterprise by Splunk
CVE-2026-76344

7.7HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76344?

A directory traversal vulnerability exists in Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. This issue allows unauthorized users, lacking 'admin' or 'power' roles, to write dispatch metadata to arbitrary locations on the host system through a crafted search identifier sent to a REST API endpoint. The lack of validation for the search identifier enables potential manipulation that could compromise system integrity. For more details, refer to the official advisory by Splunk.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.