Description
Improper Control of a Resource Through its Lifetime. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Resource Exhaustion
Action: Patch Promptly
AI Analysis

Impact

The CVE identifies a weakness in Splunk Enterprise characterized by improper control of a resource through its lifetime (CWE‑664). The description states that internal resource handling may be deficient, which can give an attacker the ability to influence the allocation, usage, or deallocation of resources. The impact of such a flaw is not explicitly stated in the CNA notes, but it is inferred from the nature of the weakness that it could lead to resource exhaustion, service instability, or denial of service.

Affected Systems

Affected systems are Splunk Enterprise deployments that run the vulnerable releases listed in the advisory – versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The fix is available in those releases and in any later versions of Splunk Enterprise.

Risk and Exploitability

No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The CNA does not supply a CVSS score, so a precise severity assessment cannot be calculated. It is inferred that exploitation of this resource‑management flaw could be achieved through legitimate user actions or by internal privileged users, potentially resulting in denial of service or other adverse effects. The lack of public exploitation evidence suggests the risk is lower than for known exploits, yet the potential impact on availability warrants prompt remediation.

Generated by OpenCVE AI on October 7, 2026 at 23:27 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to one of the patched releases (10.4.3, 10.2.7, 10.0.10, 9.4.15, or any newer version).
  • Configure resource limits for Splunk processes – set appropriate caps on memory, file descriptors, and CPU usage to mitigate the impact if the vulnerability remains present.
  • Monitor Splunk services for abnormal resource consumption or unexpected restarts and investigate any anomalies that arise.

Generated by OpenCVE AI on October 7, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Improper Control of a Resource Through its Lifetime. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Title Improper Control of a Resource Through its Lifetime in Splunk Enterprise
Weaknesses CWE-664
References

Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:38.324Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76282

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:19.700

Modified: 2026-10-07T21:17:19.700

Link: CVE-2026-76282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime