Description
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing Language version 2 (SPL2) modules belonging to other users through the data management orchestrator interface. The vulnerability does not affect Splunk Enterprise versions below 10.2. The broken object level authorization is possible because the data management orchestrator does not verify that the requesting user owns the target resources before it deletes the modules. For more information see Manage SPL2-based apps (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/meet-splunk-apps/manage-spl2-based-apps) in the Splunk documentation.
Published: 2026-08-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Splunk Enterprise versions earlier than 10.4.2 or 10.2.6 allow users without admin or power roles to delete SPL2 modules belonging to other users via the data management orchestrator. Because the orchestrator does not verify ownership before deletion, an attacker with a standard or power role can remove another user's modules, potentially disrupting searches and data ingestion. This reflects a broken object‑level authorization weakness (CWE‑639).

Affected Systems

Splunk Enterprise (Splunk) products running any supported version before 10.4.2 or before 10.2.6, but not those versions older than 10.2, are susceptible. This includes all 10.4.x, 10.2.x, and 10.0.x releases prior to the specified patch levels.

Risk and Exploitability

The CVSS score is 5.4, indicating a moderate risk. EPSS is not available, so the probability of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the REST API that the data management orchestrator uses; this inference is drawn from the description of the orchestrator interface. Attackers must have valid Splunk credentials but need not be administrators; a standard or power user can exploit the broken authorization to delete any other user's module, which could lead to loss of functionality or degraded performance.

Generated by OpenCVE AI on August 20, 2026 at 07:57 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


OpenCVE Recommended Actions

  • Install the vendor patch by upgrading Splunk Enterprise to a version that is not affected (10.4.2, 10.2.6, 10.0.9 or 9.4.14 and newer).
  • Revoke or adjust Splunk roles to ensure that only administrators or power roles can delete SPL2 modules; audit current permissions.
  • Monitor system logs for attempts to delete SPL2 modules and investigate anomalous activity.

Generated by OpenCVE AI on August 20, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Thu, 20 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing Language version 2 (SPL2) modules belonging to other users through the data management orchestrator interface. The vulnerability does not affect Splunk Enterprise versions below 10.2. The broken object level authorization is possible because the data management orchestrator does not verify that the requesting user owns the target resources before it deletes the modules. For more information see Manage SPL2-based apps (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/meet-splunk-apps/manage-spl2-based-apps) in the Splunk documentation.
Title Improper Access Control through the REST API in Splunk Enterprise
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T19:57:07.544Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76263

cve-icon Vulnrichment

Updated: 2026-08-26T19:52:03.435Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:14.447

Modified: 2026-08-26T20:18:00.680

Link: CVE-2026-76263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key