Vulnerability Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Cluster member control endpoints and change cluster state, which could allow for a denial of service. The vulnerability is possible because the Search Head Cluster member control endpoints do not require a state-changing Hypertext Transfer Protocol (HTTP) request type before they apply read-only authorization.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | >= 9.4.0, < 9.4.14 |
Related Weaknesses (CWE)
References
- https://advisory.splunk.com/advisories/SVD-2026-0801Vendor Advisory
FAQ
What is CVE-2026-76348?
CVE-2026-76348 is a vulnerability with a CVSS score of 3.8 (LOW). In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request...
How severe is CVE-2026-76348?
CVE-2026-76348 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-76348?
Check the references section above for vendor advisories and patch information. Affected products include: Splunk Splunk.