Junglewise Threat Intelligence

CVE-2026-76338: Splunk Enterprise improper authentication in distributed search REST API

CVE-2026-76338 · Severity: high · CVSS 8.1 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise, a widely-used data analytics platform deployed in corporate environments, allows unauthenticated users with access to a distributed search private key to forge administrative session tokens and gain complete system access. An attacker with this capability could steal sensitive data, modify system configuration, and disrupt search and monitoring operations across the organization.

Technical details

The vulnerability is an improper authentication flaw (CWE-287) in the distributed search token endpoint that fails to validate signed requests. When a request lacks a proper signature, the endpoint falls back to using shared local key material, permitting an attacker in possession of the distributed search private key to forge valid administrative session tokens. This is a network-reachable vulnerability requiring only knowledge of the private key; no additional authentication is required. A successful exploit grants the attacker administrative privileges, enabling data access, system integrity violation, and service disruption. Patches are available in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14.

Affected products

  • Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 (affects 10.4.0–10.4.1, 10.2.0–10.2.5, 10.0.0–10.0.8, and 9.4.0–9.4.13)

Timeline

  • 2026-08-19: disclosed

References