Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/use-the-native-splunk-platform-authentication-scheme/set-up-native-splunk-authentication) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Published: 2026-10-07
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper username validation that can corrupt per‑user configuration and enable privilege escalation
Action: Patch
AI Analysis

Impact

This vulnerability arises when a Splunk Enterprise user with the edit_user capability creates a native username ending with a period because the system fails to reject the trailing character before locating the user directory. The flaw allows distinct usernames to share per‑user configuration data, leading to unintended modifications of configuration files or user‑management actions that affect the wrong account. The result is loss of configuration integrity and potential privilege escalation if an attacker can influence another account’s settings. This issue is captured as CWE‑20, improper input validation.

Affected Systems

Splunk Enterprise deployments running any version prior to 10.4.3, 10.2.7, 10.0.10, or 9.4.15 that grant edit_user privileges through the REST API are susceptible. All roles possessing edit_user capability, including trusted administrators, are impacted.

Risk and Exploitability

The CVSS score of 4.1 indicates a moderate severity. An EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated REST API session with edit_user rights; no evidence indicates a network‑based exploitation path without such credentials. Damage is primarily limited to configuration integrity, but the ability to target another account’s configuration could facilitate privilege escalation, though the impact remains constrained compared to remote code execution.

Generated by OpenCVE AI on October 7, 2026 at 23:39 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to at least 10.4.3 (or 10.2.7, 10.0.10, or 9.4.15) as provided by the vendor
  • Restrict the edit_user capability to only trusted administrators and review role assignments for unnecessary permissions
  • Implement additional input validation or audit logging to detect and block usernames that end with a period if an immediate upgrade is not possible

Generated by OpenCVE AI on October 7, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/use-the-native-splunk-platform-authentication-scheme/set-up-native-splunk-authentication) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Title Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterprise
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-08T15:06:09.743Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76277

cve-icon Vulnrichment

Updated: 2026-10-08T15:04:51.987Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T21:17:18.900

Modified: 2026-10-08T20:08:45.857

Link: CVE-2026-76277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:45:14Z

Weaknesses
  • CWE-20

    Improper Input Validation