Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Representational State Transfer (REST) API endpoint for knowledge bundle upload does not require the high-privilege capability edit_dist_peer, and distributed search accepts caller-supplied knowledge bundle selections from users who do not hold that capability. For more information see What search heads send to search peers (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.2/knowledge-bundle-replication/what-search-heads-send-to-search-peers), About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.0/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.1/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Using the REST API reference (https://help.splunk.com/en/splunk-enterprise/rest-api-reference/10.4/introduction/using-the-rest-api-reference) in the Splunk documentation.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Splunk Enterprise allows a user who does not have the admin or power role to upload a malicious knowledge bundle through the REST API. Because the endpoint does not enforce the high‑privilege capability edit_dist_peer, the distributed search component will accept the uploaded bundle and execute it on search peers. This can lead to arbitrary code execution, allowing an attacker to read all data, alter data, and potentially disrupt system availability. The weakness is a missing authorization check, aligning with CWE‑284.

Affected Systems

Splunk Enterprise installations with versions older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are affected. The flaw is present in the knowledge bundle upload API used by distributed search clusters. All roles that are not granted the admin or power capability are vulnerable when they can reach the endpoint.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV, but the lack of a KEV listing does not reduce the risk of exploitation in a targeted scenario. An attacker with legitimate or compromised non‑admin credentials could exploit the API to deploy a malicious bundle, giving them full system access. Because the attack vector relies on allowed API usage, an exploitation opportunity exists as long as an account without the required capability can access the Splunk REST interface.

Generated by OpenCVE AI on August 20, 2026 at 09:57 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2 or later (or 10.2.6, 10.0.9, or 9.4.14 and beyond).
  • Restrict knowledge bundle upload privileges so that only users with admin or power roles can use the REST API endpoint.
  • Monitor system logs for unauthorized knowledge bundle upload activity to detect potential exploitation attempts.

Generated by OpenCVE AI on August 20, 2026 at 09:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Representational State Transfer (REST) API endpoint for knowledge bundle upload does not require the high-privilege capability edit_dist_peer, and distributed search accepts caller-supplied knowledge bundle selections from users who do not hold that capability. For more information see What search heads send to search peers (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.2/knowledge-bundle-replication/what-search-heads-send-to-search-peers), About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.0/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.1/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Using the REST API reference (https://help.splunk.com/en/splunk-enterprise/rest-api-reference/10.4/introduction/using-the-rest-api-reference) in the Splunk documentation.
Title Remote Code Execution (RCE) through the REST API in Splunk Enterprise
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:56.290Z

Reserved: 2026-08-19T12:02:03.624Z

Link: CVE-2026-76313

cve-icon Vulnrichment

Updated: 2026-08-27T16:16:54.935Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:15.117

Modified: 2026-08-27T17:20:08.200

Link: CVE-2026-76313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses