
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76352 is an improper authorization vulnerability in Splunk Enterprise that allows authenticated users without "admin" or "power" roles to create or modify scripted lookups via generic configuration endpoints and execute installed lookup scripts with the privileges of the Splunk Enterprise service account. It affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The vulnerability was published on August 19, 2026, with a patch advisory released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (Splunk Advisory, GitHub Advisory).
The root cause is CWE-285 (Improper Authorization): the generic transforms configuration endpoints in Splunk Enterprise do not enforce the capability checks required to create or edit external lookup definitions, which are normally restricted to users with "admin" or "power" roles. An authenticated low-privileged user can send crafted API requests to these endpoints to define or modify a scripted lookup pointing to an already-installed script, which Splunk then executes under the service account running the Splunk Enterprise process. No special configuration or elevated starting privileges beyond a valid Splunk account are required to exploit this flaw (Splunk Advisory, GitHub Advisory).
Successful exploitation allows any authenticated Splunk user — regardless of their assigned role — to execute arbitrary installed scripts with the full permissions of the Splunk Enterprise service account. This can result in complete confidentiality loss (access to all data indexed by Splunk), integrity compromise (modification of Splunk configurations and data), and availability impact (disruption of the Splunk service). Given that Splunk Enterprise commonly ingests sensitive security, operational, and business data, exploitation could expose an organization's entire monitored environment and facilitate lateral movement (Splunk Advisory, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and requirement of only a valid (low-privileged) Splunk account make it an attractive target for insider threats or attackers who have already obtained any Splunk credentials.
/services/data/transforms/lookups), submit a POST or PUT request to create or modify a scripted lookup definition that references an already-installed script on the Splunk server.audit.log) showing unexpected creation or modification of transforms/lookup definitions by users without "admin" or "power" roles; REST API calls to /services/data/transforms/lookups from low-privileged accounts.$SPLUNK_HOME/etc/apps/*/bin/) that were recently changed by non-admin users.Upgrade Splunk Enterprise to one of the patched versions: 10.4.2, 10.2.6, 10.0.9, or 9.4.14. As an interim workaround, restrict access to the Splunk REST API configuration endpoints and enforce strict role-based access controls to limit which users can interact with transforms configuration. Review and audit existing scripted lookup definitions for unauthorized modifications. Refer to Splunk's documentation on role capabilities and limits.conf for additional hardening guidance (Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."