Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Cluster member control endpoints and change cluster state, which could allow for a denial of service. The vulnerability is possible because the Search Head Cluster member control endpoints do not require a state-changing Hypertext Transfer Protocol (HTTP) request type before they apply read-only authorization.
Published: 2026-08-19
Score: 3.8 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from missing authorization checks on Search Head Cluster member control endpoints. A user with the list_search_head_clustering capability can issue a read request that the system treats as read‑only but actually performs a state‑changing operation. This enables the attacker to modify cluster configuration and bring the cluster into an inconsistent or unusable state, resulting in a denial of service. The flaw is identified as CWE‑862, missing authorization.

Affected Systems

All deployments of Splunk Enterprise running a version earlier than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are susceptible. Any role that contains the list_search_head_clustering capability, regardless of other permissions, can trigger this problem when the user is authenticated to the web interface.

Risk and Exploitability

The CVSS score of 3.8 indicates a low overall severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation activity. Exploitation requires an authenticated session on the Splunk web tier and possession of the list_search_head_clustering capability; therefore the attack vector is inferred to be the web interface, based on the description’s reference to read requests. The required privilege level suggests that the threat would likely arise from an insider or a compromised user account.

Generated by OpenCVE AI on August 20, 2026 at 10:57 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Remove the list_search_head_clustering capability from Splunk roles if they do not need Search Head Cluster status information. For more information see [Define roles on the Splunk platform with capabilities](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later.
  • If an upgrade is not immediately feasible, remove the list_search_head_clustering capability from any roles that do not require Search Head Cluster status information, following Splunk’s guidance on role definition.
  • Continuously monitor cluster state and access logs for unexpected changes to confirm that the capability restriction is effective.

Generated by OpenCVE AI on August 20, 2026 at 10:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Cluster member control endpoints and change cluster state, which could allow for a denial of service. The vulnerability is possible because the Search Head Cluster member control endpoints do not require a state-changing Hypertext Transfer Protocol (HTTP) request type before they apply read-only authorization.
Title Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-19T21:34:43.675Z

Reserved: 2026-08-19T12:02:03.628Z

Link: CVE-2026-76348

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T22:17:19.680

Modified: 2026-08-19T22:17:19.680

Link: CVE-2026-76348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses