Vulnerability in Splunk Enterprise Allows Unauthorized File Deletion
CVE-2026-76353

5.4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76353?

In certain versions of Splunk Enterprise, an issue allows users lacking the required 'admin' or 'power' roles to exploit the knowledge bundle delta feature. This exploitation could lead to the deletion of arbitrary files from the Splunk cluster manager, potentially compromising the system's integrity and availability. The root cause stems from inadequate restrictions on removal paths during the knowledge bundle delta processing, along with insufficient enforcement of expected authorization boundaries.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.