Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized creation or editing of scripted lookup definitions via raw configuration endpoints
Action: Patch
AI Analysis

Impact

The vulnerability allows a non‑admin, non‑power user to create or modify scripted lookup definitions through raw configuration REST API endpoints. Because the endpoints do not enforce lookup capability checks, the privileged configuration of scripted lookups can be altered by users with lesser roles, potentially enabling malicious data processing or data exfiltration. The impact is limited to configuration changes; it does not grant arbitrary code execution or full system compromise. The weakness is an improper authorization flaw (CWE‑863).

Affected Systems

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.10, and 9.4.15 are affected. Product: Splunk Enterprise (splunk.enterprise). Vendor: Splunk.

Risk and Exploitability

The CVSS score is 4.3, indicating moderate severity. EPSS data is not available, so exploitation likelihood is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector is via the REST API accessed by authenticated users with standard user roles, exploiting the lack of authorization checks on raw configuration writes.

Generated by OpenCVE AI on October 7, 2026 at 23:13 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher. After upgrading, set `scripted_lookup_raw_write_enforcement = block` in the `limits.conf` configuration file under [lookup], and then restart Splunk Enterprise. For more information see [Configuration file reference](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/configuration-file-reference/10.2.7-configuration-file-reference/limits%2Econf) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to a fixed version: 10.4.3, 10.2.7, 10.0.10, or 9.4.15 or newer.
  • After upgrading, set `scripted_lookup_raw_write_enforcement = block` in the [lookup] stanza of the limits.conf configuration file.
  • Restart Splunk Enterprise to apply the updated configuration changes.

Generated by OpenCVE AI on October 7, 2026 at 23:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.
Title Improper Authorization through the REST API in Splunk Enterprise
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:28.292Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:17.003

Modified: 2026-10-07T21:17:17.003

Link: CVE-2026-76264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:15:08Z

Weaknesses