NCSC-2026-0412
Vulnerability from csaf_ncscnl - Published: 2026-10-09 08:15 - Updated: 2026-10-09 08:15Certain versions of Splunk Enterprise prior to 10.4.2, 10.2.6, 10.0.10, and 9.4.15 contain a vulnerability allowing non-admin or non-power users to create or edit scripted lookup definitions via raw configuration endpoints due to missing external lookup capability checks.
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
vers:unknown/*
Splunk / Splunk Enterprise
|
vers:unknown/* | ||
|
vers:unknown/*
Splunk / Splunk Secure Gateway
|
vers:unknown/* |
Certain versions of Splunk Enterprise and Splunk Secure Gateway contain insufficient authorization checks in REST API endpoints, allowing non-admin users to access privileged functions and cause the gateway to sign attacker-controlled payloads.
Certain versions of Splunk Enterprise on Linux contain a vulnerability where a local user with Splunk user privileges can execute root-level commands during package upgrades due to the upgrade script trusting existing installation content.
Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 contain a vulnerability allowing users with read_o11y_content capability to inject forged log entries via the REST API due to improper neutralization of user-supplied SignalFlow content.
Splunk Enterprise versions below 10.4.3 and 10.2.7 contain a vulnerability in the Patroni REST API allowing unauthenticated network users to execute arbitrary OS commands due to missing authentication on critical configuration operations.
Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a REST API vulnerability allowing non-admin users to access nearly all search job information from other users due to insufficient job ownership validation.
Splunk Enterprise versions below 10.4.3 have a SQL injection vulnerability in SPL2 module filtering exploitable via the REST API by users with list_spl2_modules capability, while versions 10.2.x, 10.0.x, and 9.4.x are unaffected.
A denial of service vulnerability exists in Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 in the Discover Splunk Observability Cloud app due to improper input validation exploitable by low-privileged users.
Multiple versions of Splunk Enterprise and Splunk Secure Gateway contain a vulnerability that allows non-admin or non-power users to cause the Secure Gateway to sign attacker-controlled payloads due to insufficient authorization checks.
Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a vulnerability where users with run_collect capability can exploit the collect SPL command to inject attacker-controlled content into system-level messages via improper index name validation.
Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, and 10.0.10 contain a vulnerability allowing users with read_o11y_content capability to redirect outbound requests from the Splunk Observability Cloud app to attacker-controlled hosts, risking API token exposure.
Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a REST API vulnerability allowing non-admin and non-power users to access other users' search query text and job metadata due to insufficient per-user authorization enforcement.
Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, and 10.0.10 allowed low-privileged users to access original source code of the Discover Splunk Observability Cloud app via embedded source maps in JavaScript bundles, with version 9.4.x unaffected.
Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a vulnerability where users with edit_user capability can create native usernames ending with a period, leading to shared configuration data and user-management errors due to improper username validation.
Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, and 10.0.10 contain a REST API vulnerability allowing users with edit_spl2_module_permissions capability unauthorized access to SPL2 module permission grants, while version 9.4.x is unaffected.
Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a vulnerability allowing users with run_collect capability to bypass index access controls and write to internal indexes due to improper whitespace normalization in index names.
Certain versions of Splunk Enterprise and Splunk Secure Gateway contain a vulnerability allowing authenticated non-admin users to modify alert and mobile-device recipient data in App Key Value Store collections due to insufficient write access controls.
Splunk Enterprise addressed multiple internally discovered improper access control vulnerabilities across various versions, each categorized by CWE and assigned a CVE identifier.
Splunk Enterprise addressed multiple internally discovered vulnerabilities related to improper resource control, each categorized by CWE and assigned distinct CVE identifiers.
Splunk addressed multiple internally discovered vulnerabilities in various versions of Splunk Enterprise, each categorized by CWE and assigned a CVE identifier related to protection mechanism failures.
Splunk addressed multiple internally discovered vulnerabilities involving improper neutralization in various versions of Splunk Enterprise, each categorized by CWE and assigned specific CVE identifiers.
Splunk Enterprise addressed multiple internally identified vulnerabilities related to improper coding standards adherence, each categorized by CWE and assigned specific CVE identifiers.
{
"document": {
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE"
}
},
"lang": "nl",
"notes": [
{
"category": "legal_disclaimer",
"text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
},
{
"category": "description",
"text": "Splunk heeft meerdere kwetsbaarheden verholpen in Splunk Enterprise.",
"title": "Feiten"
},
{
"category": "description",
"text": "De kwetsbaarheden betreffen verschillende versies van Splunk Enterprise en omvatten onder andere onvoldoende autorisatiecontroles in REST API endpoints, waardoor niet-bevoegde gebruikers toegang kunnen krijgen tot geprivilegieerde functionaliteit of gevoelige gegevens. Sommige kwetsbaarheden maken het mogelijk voor gebruikers zonder admin- of power-rollen om configuratiewijzigingen door te voeren, payloads te laten ondertekenen, of zoekopdrachten en loggegevens van andere gebruikers in te zien. Daarnaast zijn er problemen met onjuiste validatie van invoer, zoals SQL-injectie in SPL2 modules, manipulatie van indexnamen, en het injecteren van vervalste loggegevens. Verder is er een privilege-escalatie mogelijk tijdens pakketupgrades op Linux-systemen door vertrouwen op gemanipuleerde installatie-inhoud. Ook kunnen gebruikers met bepaalde rechten de broncode van de Discover Splunk Observability Cloud app inzien door blootstelling van embedded source maps. Andere kwetsbaarheden betreffen het omzeilen van toegangsrestricties tot interne indexen, het wijzigen van alertdata en mobiele ontvangerinformatie in key-value stores, en het cre\u00ebren van gebruikersnamen met een punt aan het einde, wat leidt tot gedeelde configuratiegegevens. De kwetsbaarheden zijn aanwezig in meerdere recente versies van Splunk Enterprise en sommige ook in Splunk Secure Gateway.",
"title": "Interpretaties"
},
{
"category": "description",
"text": "Splunk heeft updates uitgebracht om de kwetsbaarheden in Splunk Enterprise te verhelpen. Zie bijgevoegde referenties voor meer informatie.",
"title": "Oplossingen"
},
{
"category": "general",
"text": "medium",
"title": "Kans"
},
{
"category": "general",
"text": "high",
"title": "Schade"
},
{
"category": "general",
"text": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"title": "CWE-89"
},
{
"category": "general",
"text": "Improper Output Neutralization for Logs",
"title": "CWE-117"
},
{
"category": "general",
"text": "Missing Authentication for Critical Function",
"title": "CWE-306"
},
{
"category": "general",
"text": "Inefficient Algorithmic Complexity",
"title": "CWE-407"
},
{
"category": "general",
"text": "Authorization Bypass Through User-Controlled Key",
"title": "CWE-639"
},
{
"category": "general",
"text": "Incorrect Permission Assignment for Critical Resource",
"title": "CWE-732"
},
{
"category": "general",
"text": "Missing Authorization",
"title": "CWE-862"
},
{
"category": "general",
"text": "Incorrect Authorization",
"title": "CWE-863"
},
{
"category": "general",
"text": "Server-Side Request Forgery (SSRF)",
"title": "CWE-918"
},
{
"category": "general",
"text": "Initialization of a Resource with an Insecure Default",
"title": "CWE-1188"
}
],
"publisher": {
"category": "coordinator",
"contact_details": "cert@ncsc.nl",
"name": "Nationaal Cyber Security Centrum",
"namespace": "https://www.ncsc.nl/"
},
"references": [
{
"category": "external",
"summary": "Reference",
"url": "https://advisory.splunk.com/advisories/SVD-2026-1001"
},
{
"category": "external",
"summary": "Reference",
"url": "https://advisory.splunk.com/advisories/SVD-2026-1002"
}
],
"title": "Kwetsbaarheden verholpen in Splunk Enterprise",
"tracking": {
"current_release_date": "2026-10-09T08:15:54.315511Z",
"generator": {
"date": "2025-08-04T16:30:00Z",
"engine": {
"name": "V.A.",
"version": "1.3"
}
},
"id": "NCSC-2026-0412",
"initial_release_date": "2026-10-09T08:15:54.315511Z",
"revision_history": [
{
"date": "2026-10-09T08:15:54.315511Z",
"number": "1.0.0",
"summary": "Initiele versie"
}
],
"status": "final",
"version": "1.0.0"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "vers:unknown/*",
"product": {
"name": "vers:unknown/*",
"product_id": "CSAFPID-1"
}
}
],
"category": "product_name",
"name": "Splunk Enterprise"
},
{
"branches": [
{
"category": "product_version_range",
"name": "vers:unknown/*",
"product": {
"name": "vers:unknown/*",
"product_id": "CSAFPID-2"
}
}
],
"category": "product_name",
"name": "Splunk Secure Gateway"
}
],
"category": "vendor",
"name": "Splunk"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-76264",
"cwe": {
"id": "CWE-863",
"name": "Incorrect Authorization"
},
"notes": [
{
"category": "other",
"text": "Incorrect Authorization",
"title": "CWE-863"
},
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.2, 10.2.6, 10.0.10, and 9.4.15 contain a vulnerability allowing non-admin or non-power users to create or edit scripted lookup definitions via raw configuration endpoints due to missing external lookup capability checks.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76264 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76264.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76264"
},
{
"cve": "CVE-2026-76265",
"notes": [
{
"category": "description",
"text": "Certain versions of Splunk Enterprise and Splunk Secure Gateway contain insufficient authorization checks in REST API endpoints, allowing non-admin users to access privileged functions and cause the gateway to sign attacker-controlled payloads.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76265 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76265.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76265"
},
{
"cve": "CVE-2026-76266",
"notes": [
{
"category": "description",
"text": "Certain versions of Splunk Enterprise on Linux contain a vulnerability where a local user with Splunk user privileges can execute root-level commands during package upgrades due to the upgrade script trusting existing installation content.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76266 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76266.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76266"
},
{
"cve": "CVE-2026-76267",
"cwe": {
"id": "CWE-117",
"name": "Improper Output Neutralization for Logs"
},
"notes": [
{
"category": "other",
"text": "Improper Output Neutralization for Logs",
"title": "CWE-117"
},
{
"category": "description",
"text": "Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 contain a vulnerability allowing users with read_o11y_content capability to inject forged log entries via the REST API due to improper neutralization of user-supplied SignalFlow content.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76267 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76267.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76267"
},
{
"cve": "CVE-2026-76268",
"cwe": {
"id": "CWE-306",
"name": "Missing Authentication for Critical Function"
},
"notes": [
{
"category": "other",
"text": "Missing Authentication for Critical Function",
"title": "CWE-306"
},
{
"category": "description",
"text": "Splunk Enterprise versions below 10.4.3 and 10.2.7 contain a vulnerability in the Patroni REST API allowing unauthenticated network users to execute arbitrary OS commands due to missing authentication on critical configuration operations.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76268 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76268.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76268"
},
{
"cve": "CVE-2026-76269",
"cwe": {
"id": "CWE-639",
"name": "Authorization Bypass Through User-Controlled Key"
},
"notes": [
{
"category": "other",
"text": "Authorization Bypass Through User-Controlled Key",
"title": "CWE-639"
},
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a REST API vulnerability allowing non-admin users to access nearly all search job information from other users due to insufficient job ownership validation.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76269 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76269.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76269"
},
{
"cve": "CVE-2026-76270",
"cwe": {
"id": "CWE-89",
"name": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)"
},
"notes": [
{
"category": "other",
"text": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"title": "CWE-89"
},
{
"category": "description",
"text": "Splunk Enterprise versions below 10.4.3 have a SQL injection vulnerability in SPL2 module filtering exploitable via the REST API by users with list_spl2_modules capability, while versions 10.2.x, 10.0.x, and 9.4.x are unaffected.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76270 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76270.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76270"
},
{
"cve": "CVE-2026-76271",
"cwe": {
"id": "CWE-407",
"name": "Inefficient Algorithmic Complexity"
},
"notes": [
{
"category": "other",
"text": "Inefficient Algorithmic Complexity",
"title": "CWE-407"
},
{
"category": "description",
"text": "A denial of service vulnerability exists in Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 in the Discover Splunk Observability Cloud app due to improper input validation exploitable by low-privileged users.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76271 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76271.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76271"
},
{
"cve": "CVE-2026-76272",
"cwe": {
"id": "CWE-862",
"name": "Missing Authorization"
},
"notes": [
{
"category": "other",
"text": "Missing Authorization",
"title": "CWE-862"
},
{
"category": "description",
"text": "Multiple versions of Splunk Enterprise and Splunk Secure Gateway contain a vulnerability that allows non-admin or non-power users to cause the Secure Gateway to sign attacker-controlled payloads due to insufficient authorization checks.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76272 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76272.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76272"
},
{
"cve": "CVE-2026-76273",
"notes": [
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a vulnerability where users with run_collect capability can exploit the collect SPL command to inject attacker-controlled content into system-level messages via improper index name validation.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76273 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76273.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76273"
},
{
"cve": "CVE-2026-76274",
"cwe": {
"id": "CWE-918",
"name": "Server-Side Request Forgery (SSRF)"
},
"notes": [
{
"category": "other",
"text": "Server-Side Request Forgery (SSRF)",
"title": "CWE-918"
},
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, and 10.0.10 contain a vulnerability allowing users with read_o11y_content capability to redirect outbound requests from the Splunk Observability Cloud app to attacker-controlled hosts, risking API token exposure.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76274 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76274.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76274"
},
{
"cve": "CVE-2026-76275",
"notes": [
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a REST API vulnerability allowing non-admin and non-power users to access other users\u0027 search query text and job metadata due to insufficient per-user authorization enforcement.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76275 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76275.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76275"
},
{
"cve": "CVE-2026-76276",
"cwe": {
"id": "CWE-1188",
"name": "Initialization of a Resource with an Insecure Default"
},
"notes": [
{
"category": "other",
"text": "Initialization of a Resource with an Insecure Default",
"title": "CWE-1188"
},
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, and 10.0.10 allowed low-privileged users to access original source code of the Discover Splunk Observability Cloud app via embedded source maps in JavaScript bundles, with version 9.4.x unaffected.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76276 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76276.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76276"
},
{
"cve": "CVE-2026-76277",
"notes": [
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a vulnerability where users with edit_user capability can create native usernames ending with a period, leading to shared configuration data and user-management errors due to improper username validation.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76277 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76277.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76277"
},
{
"cve": "CVE-2026-76278",
"cwe": {
"id": "CWE-639",
"name": "Authorization Bypass Through User-Controlled Key"
},
"notes": [
{
"category": "other",
"text": "Authorization Bypass Through User-Controlled Key",
"title": "CWE-639"
},
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, and 10.0.10 contain a REST API vulnerability allowing users with edit_spl2_module_permissions capability unauthorized access to SPL2 module permission grants, while version 9.4.x is unaffected.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76278 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76278.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76278"
},
{
"cve": "CVE-2026-76279",
"notes": [
{
"category": "description",
"text": "Certain versions of Splunk Enterprise prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15 contain a vulnerability allowing users with run_collect capability to bypass index access controls and write to internal indexes due to improper whitespace normalization in index names.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76279 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76279.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76279"
},
{
"cve": "CVE-2026-76280",
"cwe": {
"id": "CWE-732",
"name": "Incorrect Permission Assignment for Critical Resource"
},
"notes": [
{
"category": "other",
"text": "Incorrect Permission Assignment for Critical Resource",
"title": "CWE-732"
},
{
"category": "description",
"text": "Certain versions of Splunk Enterprise and Splunk Secure Gateway contain a vulnerability allowing authenticated non-admin users to modify alert and mobile-device recipient data in App Key Value Store collections due to insufficient write access controls.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76280 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76280.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76280"
},
{
"cve": "CVE-2026-76281",
"notes": [
{
"category": "description",
"text": "Splunk Enterprise addressed multiple internally discovered improper access control vulnerabilities across various versions, each categorized by CWE and assigned a CVE identifier.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76281 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76281.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76281"
},
{
"cve": "CVE-2026-76282",
"notes": [
{
"category": "description",
"text": "Splunk Enterprise addressed multiple internally discovered vulnerabilities related to improper resource control, each categorized by CWE and assigned distinct CVE identifiers.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76282 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76282.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76282"
},
{
"cve": "CVE-2026-76283",
"notes": [
{
"category": "description",
"text": "Splunk addressed multiple internally discovered vulnerabilities in various versions of Splunk Enterprise, each categorized by CWE and assigned a CVE identifier related to protection mechanism failures.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76283 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76283.json"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
"version": "3.1"
},
"products": [
"CSAFPID-1",
"CSAFPID-2"
]
}
],
"title": "CVE-2026-76283"
},
{
"cve": "CVE-2026-76284",
"notes": [
{
"category": "description",
"text": "Splunk addressed multiple internally discovered vulnerabilities involving improper neutralization in various versions of Splunk Enterprise, each categorized by CWE and assigned specific CVE identifiers.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76284 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76284.json"
}
],
"title": "CVE-2026-76284"
},
{
"cve": "CVE-2026-76285",
"notes": [
{
"category": "description",
"text": "Splunk Enterprise addressed multiple internally identified vulnerabilities related to improper coding standards adherence, each categorized by CWE and assigned specific CVE identifiers.",
"title": "Summary"
}
],
"product_status": {
"known_affected": [
"CSAFPID-1",
"CSAFPID-2"
]
},
"references": [
{
"category": "self",
"summary": "CVE-2026-76285 | NCSC-NL Website",
"url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-76285.json"
}
],
"title": "CVE-2026-76285"
}
]
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.