Splunk Enterprise Denial of Service Vulnerability in Search Head Clustering
CVE-2026-76348
3.8LOW
What is CVE-2026-76348?
In certain versions of Splunk Enterprise, a user with specific roles could exploit the Search Head Cluster member control endpoints due to insufficient validation on requests. This allows unauthorized state changes, potentially leading to service disruption and denial of service. The flaw arises because the endpoints do not enforce the necessity of a state-changing HTTP request type to authorize actions, making it a critical oversight in access control.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9