Junglewise Threat Intelligence

CVE-2026-76344: Splunk Enterprise path traversal in dispatch metadata via REST API

CVE-2026-76344 · Severity: high · CVSS 7.7 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise, a widely-used data analysis and monitoring platform, contains a vulnerability allowing unprivileged users to write files to arbitrary locations on the server. An attacker without admin privileges can exploit this by crafting a malicious search identifier and sending it to a REST API endpoint, potentially compromising system integrity, altering critical files, or disrupting normal operations.

Technical details

This is a path traversal vulnerability (CWE-22) in Splunk Enterprise's dispatch metadata handling. The root cause is insufficient validation of the search identifier parameter before it is used to construct a dispatch directory path. An unauthenticated or low-privileged user can supply a crafted search identifier to a REST API endpoint to write dispatch metadata to an arbitrary filesystem location on the host. No special authentication role (admin or power) is required. The vulnerability affects versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14; patches are available in those versions.

Affected products

  • Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, 9.4.14

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixes available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14

References