Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity, and disrupt service availability. The vulnerability is possible because the distributed search authentication token endpoint does not require a signed request to identify a configured search peer, allowing the request to fall back to shared local key material. For more information see About distributed search (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/overview-of-distributed-search/about-distributed-search) and authentication.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.2-configuration-file-reference/authentication.conf) in Splunk documentation.
Published: 2026-08-19
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated user who can read a trusted distributed search private key can forge an administrative session token against the distributed search authentication token endpoint, which does not require a signed request to identify a search peer. This flaw allows the attacker to gain full administrative access, read all data, alter system configuration, and potentially disrupt service availability. The weakness is a classic case of improper authentication as identified by CWE-287.

Affected Systems

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected. These include any deployment of Splunk Enterprise that relies on distributed search and has a trusted distributed search private key exposed.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is not available, suggesting no publicly known exploitation data. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires access to a distributed search private key; if that key is adequately protected the attack probability is low, but an internal actor or compromised system that can read the key could execute the attack readily.

Generated by OpenCVE AI on August 20, 2026 at 10:50 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher. Set `strictPeerNameValidation = true` in `authentication.conf` on every distributed node, then restart Splunk Enterprise.


Vendor Workaround

Turn off legacy distributed search token fallback by setting strictPeerNameValidation = true in the authentication.conf configuration file if you do not use distributed search peers that omit peername. Restart Splunk Enterprise on every node in the distributed environment after applying the setting. For more information see [authentication.conf](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.2-configuration-file-reference/authentication.conf) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or higher to receive the vendor fix.
  • If an immediate upgrade is not possible, enable strictPeerNameValidation by setting strictPeerNameValidation = true in authentication.conf on every distributed node and restart Splunk Enterprise, which disables the legacy distributed search token fallback.
  • Ensure that the trusted distributed search private key is stored in a secure, encrypted location with restricted file permissions, limiting access to authorized administrators only.

Generated by OpenCVE AI on August 20, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity, and disrupt service availability. The vulnerability is possible because the distributed search authentication token endpoint does not require a signed request to identify a configured search peer, allowing the request to fall back to shared local key material. For more information see About distributed search (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/overview-of-distributed-search/about-distributed-search) and authentication.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.2-configuration-file-reference/authentication.conf) in Splunk documentation.
Title Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:58.778Z

Reserved: 2026-08-19T12:02:03.627Z

Link: CVE-2026-76338

cve-icon Vulnrichment

Updated: 2026-08-27T16:17:39.747Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:18.360

Modified: 2026-08-27T17:20:16.170

Link: CVE-2026-76338

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses