Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to write events to internal indexes outside the index access configured for the role. The vulnerability is possible because Splunk Enterprise does not normalize whitespace in an index name before applying configured index-access restrictions for the role. For more information see collect (https://help.splunk.com/en/splunk-enterprise/search/spl-search-reference/10.4/search-commands/collect), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and How indexing works (https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/10.4/indexing-overview/how-indexing-works) in the Splunk documentation.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized write to internal indexes via the collect command
Action: Patch Now
AI Analysis

Impact

The vulnerability allows a user with the run_collect capability to specify index names that are not properly normalized, enabling writes to internal indexes that the role should not be able to access. This results in unauthorized data insertion, potentially compromising data integrity and leading to leakage of sensitive log information. The weakness is an input validation flaw classified as CWE-20.

Affected Systems

Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are impacted. Users running those versions on any platform are susceptible, regardless of the presence of system-level privileges.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available, suggesting no known high exploitation probability at present. The vulnerability is listed as not in the CISA KEV catalog. Exploitation requires an authenticated Splunk user with the run_collect capability; an attacker who can create or run a search can supply a crafted index name to overwrite or inject events into internal indexes beyond the role’s allowed scope. The attack vector is therefore limited to authenticated use, but the impact on internal data integrity could be significant for organizations relying on internal indexes for audit or monitoring purposes.

Generated by OpenCVE AI on October 7, 2026 at 22:55 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


Vendor Workaround

If upgrading to a fixed version is not possible, remove the `run_collect` capability from every role that does not have access to internal indexes. For more information see [Define roles on the Splunk platform with capabilities](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, or 9.4.15 or later to receive the fix.
  • If an upgrade is not immediately possible, remove the run_collect capability from any role that should not have access to internal indexes and ensure that only necessary roles retain this capability.
  • Audit role configurations to confirm that no unintended roles possess run_collect or that internal index permissions have not been inadvertently broadened, and adjust role assignments accordingly.

Generated by OpenCVE AI on October 7, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to write events to internal indexes outside the index access configured for the role. The vulnerability is possible because Splunk Enterprise does not normalize whitespace in an index name before applying configured index-access restrictions for the role. For more information see collect (https://help.splunk.com/en/splunk-enterprise/search/spl-search-reference/10.4/search-commands/collect), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and How indexing works (https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/10.4/indexing-overview/how-indexing-works) in the Splunk documentation.
Title Improper Input Validation of Index Names through the collect Command in Splunk Enterprise
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:36.840Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76279

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:19.180

Modified: 2026-10-07T21:17:19.180

Link: CVE-2026-76279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-20

    Improper Input Validation