CVE-2026-76353
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-76353 is a path traversal vulnerability in Splunk Enterprise that allows authenticated users without "admin" or "power" roles to delete arbitrary files accessible to Splunk Enterprise on a cluster manager by submitting a crafted knowledge bundle delta. It affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The vulnerability was published on August 19, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Splunk Advisory).

Technical details

The root cause is a path traversal flaw (CWE-24: Path Traversal: '../filedir') in the knowledge bundle delta processing component of Splunk Enterprise. The vulnerability arises because the delta processing logic does not restrict file removal paths to the designated staging directory, and the associated endpoint fails to enforce the expected authorization boundary — allowing low-privileged authenticated users to specify arbitrary paths for deletion. An attacker with any valid Splunk account (excluding admin/power roles) can craft a malicious knowledge bundle delta payload and submit it to the cluster manager endpoint over the network, triggering deletion of files accessible to the Splunk process (GitHub Advisory, Splunk Advisory).

Impact

Successful exploitation allows an authenticated low-privileged user to delete arbitrary files accessible to the Splunk Enterprise process on a cluster manager, directly impacting system integrity and service availability. There is no confidentiality impact, but targeted file deletion could disrupt Splunk's operational continuity, corrupt configurations, or remove critical data, potentially causing denial of service across the distributed search cluster. The scope is limited to the cluster manager host and files accessible under the Splunk process's permissions (GitHub Advisory, Splunk Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported as 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability requires low-level authentication (any valid Splunk account), making it accessible to a broader set of potential attackers in environments with many users, but the absence of a PoC and KEV listing reduces immediate risk. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify Splunk Enterprise instances running affected versions (below 10.4.2, 10.2.6, 10.0.9, or 9.4.14) with cluster manager roles enabled, using network scanning or Splunk's own web interface.
  2. Obtain low-privileged credentials: Acquire any valid Splunk account that does not hold the "admin" or "power" role — this could be a standard user account.
  3. Craft malicious knowledge bundle delta: Construct a knowledge bundle delta payload that includes a file removal directive with a path traversal sequence (e.g., ../../<target_path>) pointing outside the expected staging directory to an arbitrary file accessible by the Splunk process.
  4. Submit the crafted delta: Authenticate to the Splunk cluster manager and submit the malicious delta to the knowledge bundle replication endpoint, bypassing the authorization boundary due to insufficient access controls.
  5. Achieve arbitrary file deletion: The cluster manager processes the delta without restricting the removal path, resulting in deletion of the targeted file, which may disrupt service or corrupt Splunk configuration (Splunk Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to knowledge bundle replication endpoints on the cluster manager from accounts without admin or power roles; unexpected API calls related to bundle delta submission from low-privileged users.
  • Logs: Splunk audit logs showing knowledge bundle delta submissions by non-admin/non-power users; file deletion events in Splunk internal logs referencing paths outside the expected staging directory.
  • File System: Missing or unexpectedly deleted files in Splunk configuration directories or other paths accessible to the Splunk process; discrepancies in file integrity monitoring alerts for Splunk installation directories.
  • Process: Splunk cluster manager processes logging errors related to missing files or failed service restarts following unexpected file deletions (Splunk Advisory).

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability: upgrade Splunk Enterprise to 10.4.2, 10.2.6, 10.0.9, or 9.4.14 (or later) as appropriate for your release branch (Splunk Advisory). As an interim workaround where immediate patching is not feasible, restrict access to knowledge bundle replication endpoints to users with appropriate admin or power roles, and implement network-level controls to limit which users or systems can interact with cluster manager endpoints. Reviewing and auditing Splunk user role assignments to minimize the number of low-privileged accounts with access to cluster manager functionality is also recommended.

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management