Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs that belong to other users, including search query text, job metadata, results, and preview results, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully validate job ownership before returning search job information.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Retrieval of Search Job Information
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a user lacking admin or power roles to use a supplied job identifier to fetch detailed information from any search job of other users via the Splunk Enterprise REST API. The accessed data includes query text, metadata, full results, and preview results. The weakness stems from insufficient ownership validation in the API. The impact is the unintended disclosure of confidential search data and related metadata to unauthorized personnel.

Affected Systems

Splunk Enterprise is affected when running any of the following versions: all releases prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15. These versions lack the necessary checks to prevent non‑privileged users from accessing information belonging to other users.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The exploit probability is not quantified by EPSS, and the vulnerability is currently not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. The likely attack vector is remote, leveraging authenticated API calls, and requires only the ability to craft a request with a job ID. An attacker with a non‑admin account could simply request the job ID for a target job and retrieve its full contents.

Generated by OpenCVE AI on October 7, 2026 at 23:29 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, or 9.4.15, or higher, as specified by the vendor.
  • If an immediate upgrade is not possible, restrict REST API access for users with roles other than admin or power by implementing role‑based access control or network segmentation to block unauthorized API calls.
  • Continuously monitor API usage logs for anomalous search job retrieval activity from restricted users and generate alerts for suspicious patterns.

Generated by OpenCVE AI on October 7, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs that belong to other users, including search query text, job metadata, results, and preview results, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully validate job ownership before returning search job information.
Title Improper Access Control in Search Job Retrieval through the REST API in Splunk Enterprise
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:31.842Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76269

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:17.763

Modified: 2026-10-07T21:17:17.763

Link: CVE-2026-76269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key