
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76353 is a path traversal vulnerability in Splunk Enterprise that allows authenticated users without "admin" or "power" roles to delete arbitrary files accessible to Splunk Enterprise on a cluster manager by submitting a crafted knowledge bundle delta. It affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The vulnerability was published on August 19, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Splunk Advisory).
The root cause is a path traversal flaw (CWE-24: Path Traversal: '../filedir') in the knowledge bundle delta processing component of Splunk Enterprise. The vulnerability arises because the delta processing logic does not restrict file removal paths to the designated staging directory, and the associated endpoint fails to enforce the expected authorization boundary — allowing low-privileged authenticated users to specify arbitrary paths for deletion. An attacker with any valid Splunk account (excluding admin/power roles) can craft a malicious knowledge bundle delta payload and submit it to the cluster manager endpoint over the network, triggering deletion of files accessible to the Splunk process (GitHub Advisory, Splunk Advisory).
Successful exploitation allows an authenticated low-privileged user to delete arbitrary files accessible to the Splunk Enterprise process on a cluster manager, directly impacting system integrity and service availability. There is no confidentiality impact, but targeted file deletion could disrupt Splunk's operational continuity, corrupt configurations, or remove critical data, potentially causing denial of service across the distributed search cluster. The scope is limited to the cluster manager host and files accessible under the Splunk process's permissions (GitHub Advisory, Splunk Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported as 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability requires low-level authentication (any valid Splunk account), making it accessible to a broader set of potential attackers in environments with many users, but the absence of a PoC and KEV listing reduces immediate risk. No threat actor attribution has been reported.
../../<target_path>) pointing outside the expected staging directory to an arbitrary file accessible by the Splunk process.Splunk has released patched versions addressing this vulnerability: upgrade Splunk Enterprise to 10.4.2, 10.2.6, 10.0.9, or 9.4.14 (or later) as appropriate for your release branch (Splunk Advisory). As an interim workaround where immediate patching is not feasible, restrict access to knowledge bundle replication endpoints to users with appropriate admin or power roles, and implement network-level controls to limit which users or systems can interact with cluster manager endpoints. Reviewing and auditing Splunk user role assignments to minimize the number of low-privileged accounts with access to cluster manager functionality is also recommended.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."