Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution through Federated Search bundle selection. This could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Federated Search dispatch flow accepts caller-controlled bundle selection without enforcing the capability that manages federated providers and indexes. For more information see Security models for Federated Search for Splunk (https://help.splunk.com/en/splunk-enterprise/search/federated-search/10.4/run-federated-searches-across-other-splunk-deployments/service-accounts-and-security-for-federated-search-for-splunk/security-models-for-federated-search-for-splunk) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low-privileged Splunk user lacking the fsh_manage capability can trigger remote code execution by selecting a federated search bundle. The flaw allows arbitrary code execution, granting the attacker access to all relevant data and threatening system integrity and availability. The issue arises because the Federated Search dispatch flow accepts caller-controlled bundle selection without enforcing the necessary capability check, which corresponds to the missing authorization weakness identified as CWE-862.

Affected Systems

Splunk Enterprise users running any version older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are affected. All other vendors or newer versions are not impacted. The vulnerability specifically targets the Splunk Enterprise platform's Federated Search functionality.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw can be triggered through a normal user interface or API by a low-privileged account, exploitation is likely feasible in environments where Federated Search is enabled and roles are not properly restricted. An attacker would need only local or network access to the Splunk server and could exploit the capability mismatch to execute code, potentially compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 20, 2026 at 09:55 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to at least version 10.4.2, 10.2.6, 10.0.9, or 9.4.14 depending on your baseline, ensuring the fsh_manage capability check is restored.
  • Review role definitions to confirm that only privileged users have the fsh_manage capability, and reassign or remove it from lower‑privileged accounts.
  • If an immediate upgrade is not possible, consider disabling Federated Search or restricting its usage to trusted deployments until the patch can be applied.

Generated by OpenCVE AI on August 20, 2026 at 09:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution through Federated Search bundle selection. This could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Federated Search dispatch flow accepts caller-controlled bundle selection without enforcing the capability that manages federated providers and indexes. For more information see Security models for Federated Search for Splunk (https://help.splunk.com/en/splunk-enterprise/search/federated-search/10.4/run-federated-searches-across-other-splunk-deployments/service-accounts-and-security-for-federated-search-for-splunk/security-models-for-federated-search-for-splunk) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Title Remote Code Execution (RCE) through Federated Search in Splunk Enterprise
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:57.079Z

Reserved: 2026-08-19T12:02:03.625Z

Link: CVE-2026-76319

cve-icon Vulnrichment

Updated: 2026-08-27T16:17:09.658Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:15.880

Modified: 2026-08-27T17:20:10.893

Link: CVE-2026-76319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses