Description
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service disruption. The vulnerability does not affect Splunk Enterprise versions below 10.2. The vulnerability is possible because the SPL2 module management REST API does not sufficiently authorize and validate module deletion requests. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.
Published: 2026-08-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Splunk Enterprise versions below 10.4.2 and 10.2.6, the SPL2 module management REST API does not properly authorize delete requests, allowing users who do not hold the admin or power roles to remove all SPL2 modules across every app and user. This can erase exported datasets, functions, and other configurations, compromising data integrity and causing partial service disruption.

Affected Systems

Splunk Enterprise installations on any release prior to 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score is not available, and the vulnerability is not listed in CISA KEV, so no public exploitation has been reported. Attackers can exploit the flaw remotely through the exposed REST API, requiring legitimate Splunk credentials and a role that is neither admin nor power.

Generated by OpenCVE AI on August 20, 2026 at 10:16 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to the latest supported release (10.4.2, 10.2.6, 10.0.9, or 9.4.14) or newer.
  • If an upgrade cannot be performed immediately, restrict or disable the SPL2 module management REST API for users lacking admin or power roles through Splunk configuration or an external API gateway.
  • Review and tighten role‑based access controls to ensure only privileged users can perform module deletion operations.

Generated by OpenCVE AI on August 20, 2026 at 10:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service disruption. The vulnerability does not affect Splunk Enterprise versions below 10.2. The vulnerability is possible because the SPL2 module management REST API does not sufficiently authorize and validate module deletion requests. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.
Title Improper Access Control through the REST API in Splunk Enterprise
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:21:55.211Z

Reserved: 2026-08-19T12:02:03.627Z

Link: CVE-2026-76336

cve-icon Vulnrichment

Updated: 2026-08-26T14:49:33.711Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:18.093

Modified: 2026-08-26T16:16:40.250

Link: CVE-2026-76336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:30:03Z

Weaknesses