Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible because the embedded report authorization flow does not block dispatch archive download requests before Splunk Enterprise begins sending the archive to the requester. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation.
Published: 2026-08-19
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Splunk Enterprise, an attacker can acquire an embedded report token without authentication. When the token is used, a request to download the dispatch archive for the embedded report is accepted, and the system begins delivering the full archive before applying any access checks. Because the download is sent with the session context that owns the data, the attacker can retrieve the complete results of the report job, effectively bypassing the normal authorization controls. This flaw falls under CWE‑284, which describes incorrect authorization.

Affected Systems

The flaw affects Splunk Enterprise installations running versions earlier than 10.4.2, 10.2.6, 10.0.9, or 9.4.14. Any instance that provides embedded report functionality and accepts report tokens without imposing stricter authorization on archive downloads is vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS base score of 9.4, indicating a very high severity. EPSS data is not available, but the lack of listing in the CISA KEV catalog does not diminish the severity because the attack requires only the report token and no elevated privileges. The likely attack vector is a remote request from an unauthenticated client that has been able to obtain a legitimate embedded report token, a scenario that can arise if report URLs are exposed or if an internal user inadvertently shares a token. Given this, the risk of exploitation remains high, and the integrity of data on the Splunk instance could be compromised if the flaw is leveraged.

Generated by OpenCVE AI on August 20, 2026 at 10:57 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Turn off report embedding globally by setting allowEmbedTokenAuth = false in the server.conf configuration file if you do not use embedded report functionality. For more information see [Additional configuration for embedded reports](https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and [Embed scheduled reports](https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, or 9.4.14, or a newer supported release, following the official advisories
  • Turn off report embedding globally by setting allowEmbedTokenAuth = false in the server.conf configuration file to disable embedded report functionality
  • Verify that embedded report URLs are not publicly exposed and restrict distribution of embedded report tokens to authorized personnel only

Generated by OpenCVE AI on August 20, 2026 at 10:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible because the embedded report authorization flow does not block dispatch archive download requests before Splunk Enterprise begins sending the archive to the requester. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation.
Title Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:55.952Z

Reserved: 2026-08-19T12:02:03.624Z

Link: CVE-2026-76311

cve-icon Vulnrichment

Updated: 2026-08-27T16:16:49.081Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:14.837

Modified: 2026-08-27T17:20:07.147

Link: CVE-2026-76311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses