AI analysis
CVE-2026-76281 is an improper access control flaw (CWE-284) in Splunk Enterprise that Splunk found internally and fixed with a group of weaknesses, one CVE per weakness type. The provided advisory text does not describe how the flaw is triggered or what specific access an attacker gains beyond actions that access controls should have blocked. Splunk addressed it in Splunk Enterprise 10.4.3, 10.2.7, 10.0.10, and 9.4.15; earlier builds on those lines are the plausible affected set, but exact ranges are not given. A related headline about a critical 9.8 unauthenticated remote command execution bug refers to the same patch cycle and should not be treated as the impact of this CVE. It is not yet CVSS-scored, is not in CISA KEV, and no public proof of concept or in-the-wild exploitation is known.
What to do: Upgrade Splunk Enterprise to the fixed release for your branch: 10.4.3, 10.2.7, 10.0.10, or 9.4.15, and confirm the exact range in Splunk's advisory because this record does not list vulnerable versions. Until then, restrict Splunk management interfaces to trusted networks and review access logs for unexpected privilege use. Do not assume this CVE is the unauthenticated remote command execution issue described in related patch headlines.
Affected
| Splunk Enterprise | Addressed in 10.4.3, 10.2.7, 10.0.10, and 9.4.15; exact vulnerable ranges are not stated in the provided data |
Estimated exposure
largeon the order of tens of thousands of Splunk Enterprise deployments — Splunk Enterprise is a widely deployed enterprise SIEM and log platform, so affected installations are likely in the tens of thousands; this is an order-of-magnitude estimate, not a measured count of internet-exposed systems.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.