
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76354 is an arbitrary file write vulnerability in Splunk Enterprise's Search Head Clustering (SHC) bundle replication mechanism, allowing authenticated low-privilege users to delete or overwrite files on non-captain search head cluster members. It affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The vulnerability was published on August 19, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Splunk Advisory).
The root cause is classified as CWE-158 (Improper Neutralization of Null Byte or NUL Character). The Search Head Clustering bundle replication process fails to validate the name of replicated bundle files and does not neutralize NUL bytes before constructing the member bundle path, enabling path manipulation attacks (related to CAPEC-52: Embedding NULL Bytes and CAPEC-53: Postfix, Null Terminate, and Backslash). An attacker with any valid Splunk account — excluding the "admin" or "power" roles — can send a crafted REST API request over the network to exploit this flaw, requiring no user interaction and low attack complexity. The attack targets non-captain search head cluster members and operates with the file system privileges of the Splunk Enterprise service account (GitHub Advisory, Splunk Advisory).
Successful exploitation allows an authenticated low-privilege user to delete or temporarily overwrite files accessible to the Splunk Enterprise service account on non-captain search head cluster members, resulting in high integrity and high availability impact with no confidentiality loss. This could disrupt Splunk's search and monitoring operations, corrupt configuration or data files, or potentially escalate to code execution by overwriting executable or configuration files (classified as "Arbitrary File Write to Code Execution" by Feedly threat intelligence). The scope is limited to non-captain cluster members, but in a multi-node SHC deployment this could affect multiple nodes (GitHub Advisory, Splunk Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid (low-privilege) Splunk account and network access to a search head cluster member, which somewhat limits the attack surface compared to unauthenticated vulnerabilities (GitHub Advisory, Splunk Advisory).
%00) within the bundle file name parameter to manipulate the resulting file path on the target member.%00) or unusual characters in bundle file name parameters.splunkd.log) showing REST API requests to bundle replication endpoints from low-privilege users; file system errors or unexpected file operations logged by the Splunk service account on non-captain cluster members.Splunk has released patched versions addressing this vulnerability: 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Organizations should upgrade to one of these versions as the primary remediation. As interim mitigations, restrict REST API access to trusted users and networks, implement network segmentation to limit access to search head cluster members, and enforce strict role-based access controls to ensure users have only necessary privileges (Splunk Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."