CVE-2026-76354
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-76354 is an arbitrary file write vulnerability in Splunk Enterprise's Search Head Clustering (SHC) bundle replication mechanism, allowing authenticated low-privilege users to delete or overwrite files on non-captain search head cluster members. It affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The vulnerability was published on August 19, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Splunk Advisory).

Technical details

The root cause is classified as CWE-158 (Improper Neutralization of Null Byte or NUL Character). The Search Head Clustering bundle replication process fails to validate the name of replicated bundle files and does not neutralize NUL bytes before constructing the member bundle path, enabling path manipulation attacks (related to CAPEC-52: Embedding NULL Bytes and CAPEC-53: Postfix, Null Terminate, and Backslash). An attacker with any valid Splunk account — excluding the "admin" or "power" roles — can send a crafted REST API request over the network to exploit this flaw, requiring no user interaction and low attack complexity. The attack targets non-captain search head cluster members and operates with the file system privileges of the Splunk Enterprise service account (GitHub Advisory, Splunk Advisory).

Impact

Successful exploitation allows an authenticated low-privilege user to delete or temporarily overwrite files accessible to the Splunk Enterprise service account on non-captain search head cluster members, resulting in high integrity and high availability impact with no confidentiality loss. This could disrupt Splunk's search and monitoring operations, corrupt configuration or data files, or potentially escalate to code execution by overwriting executable or configuration files (classified as "Arbitrary File Write to Code Execution" by Feedly threat intelligence). The scope is limited to non-captain cluster members, but in a multi-node SHC deployment this could affect multiple nodes (GitHub Advisory, Splunk Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid (low-privilege) Splunk account and network access to a search head cluster member, which somewhat limits the attack surface compared to unauthenticated vulnerabilities (GitHub Advisory, Splunk Advisory).

Exploitation steps

  1. Reconnaissance: Identify Splunk Enterprise deployments running in Search Head Cluster (SHC) mode with versions below 10.4.2, 10.2.6, 10.0.9, or 9.4.14. Determine which nodes are non-captain cluster members, as the vulnerability only affects those.
  2. Obtain low-privilege credentials: Authenticate to the Splunk instance using any valid account that does not hold the "admin" or "power" role.
  3. Craft malicious REST API request: Construct a REST API request targeting the SHC bundle replication endpoint, embedding a NUL byte (e.g., %00) within the bundle file name parameter to manipulate the resulting file path on the target member.
  4. Trigger file deletion or overwrite: Send the crafted request to a non-captain search head cluster member. The server constructs the bundle path without sanitizing the NUL byte, causing it to write to or delete an unintended file location writable by the Splunk service account.
  5. Achieve impact: Depending on the targeted file, the attacker can disrupt Splunk availability (by deleting critical files), corrupt data integrity (by overwriting configuration or data files), or potentially escalate to code execution by overwriting scripts or binaries executed by the Splunk process (GitHub Advisory, Splunk Advisory).

Indicators of compromise

  • Network: Unusual REST API requests to SHC bundle replication endpoints from accounts without "admin" or "power" roles; unexpected API calls containing NUL bytes (%00) or unusual characters in bundle file name parameters.
  • Logs: Splunk internal logs (splunkd.log) showing REST API requests to bundle replication endpoints from low-privilege users; file system errors or unexpected file operations logged by the Splunk service account on non-captain cluster members.
  • File System: Unexpected deletion or modification of files in the Splunk installation or data directories on non-captain search head cluster members; timestamps on configuration or executable files inconsistent with normal operations.
  • Process: Unexpected processes spawned by the Splunk service account following file overwrites, which could indicate escalation to code execution.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability: 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Organizations should upgrade to one of these versions as the primary remediation. As interim mitigations, restrict REST API access to trusted users and networks, implement network segmentation to limit access to search head cluster members, and enforce strict role-based access controls to ensure users have only necessary privileges (Splunk Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management