Junglewise Threat Intelligence

CVE-2026-76354: Splunk Enterprise file deletion via Search Head Cluster bundle replication

CVE-2026-76354 · Severity: high · CVSS 8.1 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise is a data analytics platform used to search, monitor, and analyze machine-generated data. Unprivileged users can exploit a vulnerability in Search Head Cluster bundle replication to delete or overwrite files on non-captain search head cluster members, potentially disrupting operations or compromising system integrity. This could allow attackers to degrade analytics availability or corrupt critical data pipelines.

Technical details

The vulnerability is a file deletion/overwrite flaw in Search Head Cluster (SHC) bundle replication, affecting Splunk Enterprise versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The root cause is insufficient validation of replicated bundle file names and inadequate NUL byte sanitization when constructing member bundle paths. An unauthenticated or low-privileged user can send a crafted REST API request that exploits this path traversal opportunity to delete or overwrite files writable by the Splunk Enterprise service account. The attack requires network access to the REST API and targets non-captain search head cluster members. Patches are available in the fixed versions listed above.

Affected products

  • Splunk Enterprise versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14

Timeline

  • 2026-08-19: disclosed

References