Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API request that deletes or temporarily overwrites files writable by the user account running Splunk Enterprise processes on a non-captain search head cluster member. The vulnerability is possible because Search Head Clustering bundle replication does not validate the name of a replicated bundle file or neutralize NUL bytes before constructing the member bundle path. For more information see About search head clustering (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/overview-of-search-head-clustering/about-search-head-clustering), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Secure Splunk Enterprise service accounts (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.0/install-splunk-enterprise-securely/secure-splunk-enterprise-service-accounts) in the Splunk documentation.
Published: 2026-08-19
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient validation of the bundle file names during search head cluster replication, allowing a crafted REST API request to cause the Splunk Enterprise process to delete or temporarily overwrite any writable file on the non‑captain member. This changes critical system files, leading to loss of data and disruption of Splunk services, directly compromising the integrity and availability of the platform. The weakness is classified as a path‑traversal flaw (CWE‑158).

Affected Systems

Affected are Splunk Enterprise deployments running any version older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 that are configured as non‑captain search head cluster members. A user who does not have the admin or power role can exploit the issue through the REST API.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score is not available, making it unclear how often it is expected to be exploited. The vulnerability is not listed in the CISA KEV catalog. An attacker would need network access to the Splunk REST interface and only needs an account with a non‑admin role; the lack of validation of bundle names and NUL byte neutralization is the main exploitation vector. The likely attack vector is through a crafted REST API request from an external user or compromised account.

Generated by OpenCVE AI on August 20, 2026 at 09:49 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


OpenCVE Recommended Actions

  • Update Splunk Enterprise to the patched versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or newer.
  • Restrict the bundle‑replication REST API permissions so that only users with the admin or power roles can invoke them.
  • Run the Splunk service accounts under dedicated service users with the least‑privilege file system permissions to limit potential file deletions.

Generated by OpenCVE AI on August 20, 2026 at 09:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Thu, 20 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API request that deletes or temporarily overwrites files writable by the user account running Splunk Enterprise processes on a non-captain search head cluster member. The vulnerability is possible because Search Head Clustering bundle replication does not validate the name of a replicated bundle file or neutralize NUL bytes before constructing the member bundle path. For more information see About search head clustering (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/overview-of-search-head-clustering/about-search-head-clustering), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Secure Splunk Enterprise service accounts (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.0/install-splunk-enterprise-securely/secure-splunk-enterprise-service-accounts) in the Splunk documentation.
Title Path Traversal through Search Head Clustering in Splunk Enterprise
Weaknesses CWE-158
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:35.131Z

Reserved: 2026-08-19T12:02:03.628Z

Link: CVE-2026-76354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:20.463

Modified: 2026-08-21T19:19:17.933

Link: CVE-2026-76354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses
  • CWE-158

    Improper Neutralization of Null Byte or NUL Character