Junglewise Threat Intelligence

CVE-2026-76345: Splunk Enterprise search head cluster REST API path traversal and RCE

CVE-2026-76345 · Severity: medium · CVSS 6 · Published 2026-08-19

Technologies: Splunk Enterprise, Splunk. Vendors: Splunk.

Executive brief

Splunk Enterprise, a widely-used log analysis and data platform, contains a vulnerability in its search head cluster management API that allows privileged users to write arbitrary files to the server's filesystem. An attacker with high-privilege clustering management roles could exploit this to execute arbitrary code on the Splunk server, potentially compromising all indexed data and disrupting analytics operations for downstream customers and internal monitoring.

Technical details

The search head cluster member bundle REST API in Splunk Enterprise versions below 10.4.2 fails to properly enforce authorization boundaries and does not validate bundle paths before accepting bundle content. This allows high-privilege users with search head clustering management permissions to write files to arbitrary locations writable by the Splunk process user. An authenticated attacker could leverage this to place malicious code in executable locations, resulting in remote code execution within the Splunk Enterprise context. The vulnerability requires high-privilege clustering management role membership and network access to the REST API; patches are available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.

Affected products

  • Splunk Enterprise 10.4.0-10.4.1, 10.2.0-10.2.5, 10.0.0-10.0.8, 9.4.0-9.4.13

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Patches released for versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14

References

Related threats