Description
Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Improper Access Control
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a flaw in Splunk Enterprise that allows unauthorized access to data or functionality due to improper access control. It is classified as CWE-284, indicating a weakness where restrictive access controls are not correctly enforced. Because the flaw can allow an attacker to bypass intended restrictions, it could lead to theft or modification of sensitive information, or elevation of privileges within the Splunk deployment.

Affected Systems

Splunk Enterprise builds that have not incorporated the fixes released in versions 10.4.3, 10.2.7, 10.0.10, or 9.4.15 are potentially vulnerable. The advisory does not enumerate explicitly which older revisions remain affected, but any deployment running code that predates these patches should be evaluated for risk.

Risk and Exploitability

Although no EPSS or CVSS score is available and it is not listed in the CISA KEV catalog, the flaw’s inherent nature as an improper access control mechanism allows an attacker who has network access to the Splunk deployment to bypass normal authorization checks. This could enable the attacker to read or modify data, or perform actions beyond the intended privilege level.

Generated by OpenCVE AI on October 7, 2026 at 23:28 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, 9.4.15, or a later release to apply the vendor's fix.
  • Restrict access to the Splunk web interface and API to trusted internal networks or VPNs only to reduce the attack surface.
  • Review and enforce role‑based access controls within Splunk to ensure that users possess only the minimum permissions required for their duties.

Generated by OpenCVE AI on October 7, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Title Improper Access Control in Splunk Enterprise
Weaknesses CWE-284
References

Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:37.805Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76281

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:19.483

Modified: 2026-10-07T21:17:19.483

Link: CVE-2026-76281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses