Description
Protection Mechanism Failure. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Splunk Enterprise is classified as a protection mechanism failure. Splunk identified multiple internally discovered flaws that could allow an attacker to bypass the system's safeguards, potentially enabling privilege escalation or unauthorized access to protected data or functionality, thereby compromising confidentiality and integrity.

Affected Systems

The affected product is Splunk Enterprise. Vulnerable versions are all releases older than Splunk Enterprise 10.4.3, 10.2.7, 10.0.10, or 9.4.15; any releases prior to those patched versions are at risk.

Risk and Exploitability

EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, indicating no publicly disclosed exploit. The advisory does not provide an explicit attack vector; based on typical scenarios for protection mechanism failures, the likely attack vector could be remote through exposed interfaces, although this is inferred. The CVSS rating is not disclosed in the provided data, so the exact severity cannot be quantified. The weakness type (CWE-693) suggests a high potential for unauthorized access if exploited.

Generated by OpenCVE AI on October 7, 2026 at 23:27 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading Splunk Enterprise to the minimum patched versions (10.4.3, 10.2.7, 10.0.10, or 9.4.15) or a newer release.
  • Restrict network access to the Splunk Enterprise instance and enforce role‑based access controls to limit the potential for an attacker to exploit the failure before patching.
  • Enable audit logging and monitor logs for anomalous activity that may indicate an attempt to bypass protection mechanisms.

Generated by OpenCVE AI on October 7, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Protection Mechanism Failure. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Title Protection Mechanism Failure in Splunk Enterprise
Weaknesses CWE-693
References

Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:38.794Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76283

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:19.987

Modified: 2026-10-07T21:17:19.987

Link: CVE-2026-76283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure