Splunk Enterprise versions 9.4.x are not affected.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-1001 |
|
Wed, 07 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State Transfer (REST) API to access permission grants for SPL2 modules that the user does not have permission to view. The vulnerability is possible because Splunk Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. For more information see Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) and Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected. | |
| Title | Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-10-07T20:46:36.393Z
Reserved: 2026-08-19T12:02:03.621Z
Link: CVE-2026-76278
No data.
Status : Received
Published: 2026-10-07T21:17:19.043
Modified: 2026-10-07T21:17:19.043
Link: CVE-2026-76278
No data.
OpenCVE Enrichment
No data.
-
CWE-639
Authorization Bypass Through User-Controlled Key