Description
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all relevant data and system integrity available to the user account running Splunk Enterprise. The vulnerability is possible because the Windows management-port listener does not apply exclusive address binding protections before the service starts.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local Windows user can pre‑bind to the Splunk management port before the Splunk Enterprise service starts, intercept authentication tokens from child processes, and use those tokens to gain full access to all data and system integrity that the Splunk service account normally holds. This flaw arises because the Windows listener does not enforce exclusive address binding prior to startup, allowing a local attacker to hijack the token exchange and effectively inject credentials into the Splunk environment. The result is that a user who would normally only have limited local rights can climb to the privileges associated with the Splunk service account, which may include sensitive data, configuration, and administrative actions. The weakness is classified as CWE‑269: Improper Privilege Management.

Affected Systems

Splunk Enterprise running on Windows versions prior to 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14 is vulnerable. Any deployment of these affected releases that exposes the management port to local users is at risk.

Risk and Exploitability

The stored CVSS score of 8.8 indicates a high severity attack. Because the flaw requires local user access to the Windows host, the attack vector is local, and the attacker can exploit the vulnerability after binding to the port before Splunk starts. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so while it remains a critical local privilege escalation issue, there is no known public exploitation data at this time. Administrators should treat it as a high‑priority issue and proceed with remediation as soon as possible.

Generated by OpenCVE AI on August 20, 2026 at 09:58 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to a fixed release such as 10.4.2, 10.2.6, 10.0.9, 9.4.14, or newer, following the vendor’s guidance.
  • Reconfigure Splunk to bind its management port exclusively to the loopback interface (127.0.0.1) so that only the Splunk service account can listen or bind to that port.
  • Apply Windows ACL or firewall restrictions to block non‑service accounts from binding to or accessing the management port, ensuring that token interception cannot occur from local users.

Generated by OpenCVE AI on August 20, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows
Splunk splunk

Wed, 19 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all relevant data and system integrity available to the user account running Splunk Enterprise. The vulnerability is possible because the Windows management-port listener does not apply exclusive address binding protections before the service starts.
Title Improper Privilege Management on the Management Port in Splunk Enterprise for Windows
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Microsoft Windows
Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:55.649Z

Reserved: 2026-08-19T12:02:03.619Z

Link: CVE-2026-76259

cve-icon Vulnrichment

Updated: 2026-08-27T16:16:43.127Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:13.927

Modified: 2026-08-27T17:20:06.080

Link: CVE-2026-76259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management