CVE-2026-76352
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-76352 is an improper authorization vulnerability in Splunk Enterprise that allows authenticated users without "admin" or "power" roles to create or modify scripted lookups via generic configuration endpoints and execute installed lookup scripts with the privileges of the Splunk Enterprise service account. It affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The vulnerability was published on August 19, 2026, with a patch advisory released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (Splunk Advisory, GitHub Advisory).

Technical details

The root cause is CWE-285 (Improper Authorization): the generic transforms configuration endpoints in Splunk Enterprise do not enforce the capability checks required to create or edit external lookup definitions, which are normally restricted to users with "admin" or "power" roles. An authenticated low-privileged user can send crafted API requests to these endpoints to define or modify a scripted lookup pointing to an already-installed script, which Splunk then executes under the service account running the Splunk Enterprise process. No special configuration or elevated starting privileges beyond a valid Splunk account are required to exploit this flaw (Splunk Advisory, GitHub Advisory).

Impact

Successful exploitation allows any authenticated Splunk user — regardless of their assigned role — to execute arbitrary installed scripts with the full permissions of the Splunk Enterprise service account. This can result in complete confidentiality loss (access to all data indexed by Splunk), integrity compromise (modification of Splunk configurations and data), and availability impact (disruption of the Splunk service). Given that Splunk Enterprise commonly ingests sensitive security, operational, and business data, exploitation could expose an organization's entire monitored environment and facilitate lateral movement (Splunk Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and requirement of only a valid (low-privileged) Splunk account make it an attractive target for insider threats or attackers who have already obtained any Splunk credentials.

Exploitation steps

  1. Obtain valid credentials: Acquire any valid Splunk Enterprise user account — even a low-privileged one without "admin" or "power" roles — through phishing, credential stuffing, or other means.
  2. Identify target instance: Locate an internet-facing or network-accessible Splunk Enterprise instance running a vulnerable version (below 10.4.2, 10.2.6, 10.0.9, or 9.4.14).
  3. Authenticate to Splunk: Log in to the Splunk REST API or web interface using the obtained credentials to obtain a valid session token.
  4. Craft malicious scripted lookup definition: Using the generic transforms configuration endpoint (e.g., via the Splunk REST API at /services/data/transforms/lookups), submit a POST or PUT request to create or modify a scripted lookup definition that references an already-installed script on the Splunk server.
  5. Trigger script execution: Invoke the scripted lookup (e.g., by running a Splunk search that references the modified lookup) to cause Splunk to execute the target script under the service account's privileges.
  6. Achieve objective: The script runs with Splunk service account permissions, enabling data exfiltration, configuration tampering, or further system compromise (Splunk Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Splunk audit logs (audit.log) showing unexpected creation or modification of transforms/lookup definitions by users without "admin" or "power" roles; REST API calls to /services/data/transforms/lookups from low-privileged accounts.
  • Logs: Splunk search logs showing searches that invoke scripted lookups not previously associated with the triggering user account.
  • Process: Unexpected child processes spawned by the Splunk service account (e.g., Python scripts, shell commands) that are not part of normal Splunk operations.
  • File System: New or modified lookup script files in the Splunk apps directory (e.g., $SPLUNK_HOME/etc/apps/*/bin/) that were recently changed by non-admin users.
  • Network: Unusual outbound network connections originating from the Splunk server process to external IPs, potentially indicating data exfiltration or reverse shell activity.

Mitigation and workarounds

Upgrade Splunk Enterprise to one of the patched versions: 10.4.2, 10.2.6, 10.0.9, or 9.4.14. As an interim workaround, restrict access to the Splunk REST API configuration endpoints and enforce strict role-based access controls to limit which users can interact with transforms configuration. Review and audit existing scripted lookup definitions for unauthorized modifications. Refer to Splunk's documentation on role capabilities and limits.conf for additional hardening guidance (Splunk Advisory).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management