Description
Improper Adherence to Coding Standards. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Published: 2026-10-07
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Impact Undisclosed
Action: Assess Impact
AI Analysis

Impact

The advisory notes multiple internally identified vulnerabilities in Splunk Enterprise that stem from improper adherence to coding standards – a weakness catalogued as CWE‑710. The released security notes do not detail the exact defect or the resulting security consequences, leaving the effect on confidentiality, integrity, or availability unspecified. Because the description cites only a broad coding‑standard violation, the precise impact cannot be determined from the available information.

Affected Systems

Splunk Enterprise users running versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are affected. Earlier releases that have not incorporated the identified fixes remain vulnerable, and any deployment that has not been upgraded to at least the specified patch level remains at risk.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in CISA KEV, indicating no public exploitation evidence currently. The lack of an assigned CVSS score also prevents a quantitative severity assessment. Although the advisory does not describe an exposed external interface, it is inferred that the exploit might require an internal code‑execution path or additional weaknesses to be exploitable. Given the absence of public exploits and the undefined impact, the overall risk may be considered low to uncertain until further details emerge.

Generated by OpenCVE AI on October 7, 2026 at 23:26 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, 9.4.15, or any later release that incorporates the fix
  • Apply network segmentation or firewall rules to limit external access to Splunk services and restrict untrusted network traffic
  • Monitor Splunk logs and network events for abnormal authentication attempts or errors that could indicate exploitation of the coding‑standard vulnerability

Generated by OpenCVE AI on October 7, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Improper Adherence to Coding Standards. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Title Improper Adherence to Coding Standards in Splunk Enterprise
Weaknesses CWE-710
References

Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:39.808Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:20.250

Modified: 2026-10-07T21:17:20.250

Link: CVE-2026-76285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses
  • CWE-710

    Improper Adherence to Coding Standards