8.1

CVE-2026-76338

Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity, and disrupt service availability. The vulnerability is possible because the distributed search authentication token endpoint does not require a signed request to identify a configured search peer, allowing the request to fall back to shared local key material. For more information see About distributed search (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/overview-of-distributed-search/about-distributed-search) and authentication.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.2-configuration-file-reference/authentication.conf) in Splunk documentation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Splunk ≫ Splunk SwEdition enterprise Version >= 9.4.0 < 9.4.14
Splunk ≫ Splunk SwEdition enterprise Version >= 10.0.0 < 10.0.9
Splunk ≫ Splunk SwEdition enterprise Version >= 10.2.0 < 10.2.6
Splunk ≫ Splunk SwEdition enterprise Version >= 10.4.0 < 10.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.2
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Cisco PSIRT 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://advisory.splunk.com/advisories/SVD-2026-0801
Vendor Advisory