NCSC-2026-0322 [1.00] [M/H] Vulnerabilities fixed in Splunk Enterprise by Splunk
Splunk has fixed multiple vulnerabilities in Splunk Enterprise, specifically in versions prior to 10.4.2, 10.2.6, 10.0.9 and 9.4.14. The vulnerabilities in Splunk Enterprise include: - Insufficient enforcement of authentication and authorization controls in REST APIs, allowing unauthorized users to gain access to sensitive data, configurations and leading to execution of arbitrary SPL commands with elevated privileges. - Multiple vulnerabilities that enable Cross-Site Scripting (XSS), where attackers can inject and execute JavaScript through specially crafted links or content in the context of other users. - Furthermore, unauthenticated or low-privileged users can execute commands, manipulate files, or modify configurations via various components such as Dataset Explorer, Dashboard Studio, Search Head Cluster, and other interfaces. - Some vulnerabilities make it possible to access session data, intercept authentication tokens, or force administrative sessions. Exploitation can occur via phishing, opening malicious links, or abuse of insufficiently secured API endpoints. The vulnerabilities affect various components such as the REST API, Splunk Web Manager, Dashboard Studio, federated search, and the Edge Processor component. The impact includes unauthorized access to data, manipulation of system configurations, execution of code with elevated privileges, and potential disruption of service availability. In addition to the mentioned vulnerabilities, Splunk has also released updates to fix vulnerabilities in third-party products used by Splunk. Updates for these vulnerabilities have been released previously and Splunk has now incorporated them into its own software stack.
CSIRTS triage
- What
- Multiple vulnerabilities in Splunk Enterprise include insufficient authentication and authorization controls allowing unauthorized access, privilege escalation via REST APIs, cross-site scripting, and arbitrary command execution.
- Who is affected
- Splunk Enterprise deployments running versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected.
- Urgency
- High urgency; authentication bypass and privilege escalation vulnerabilities enable unauthorized access to sensitive data and arbitrary command execution with elevated privileges.
- Action
- Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later to resolve CVE-2026-76251 through CVE-2026-76258.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Splunk Enterprise
Get an email when a new Splunk Enterprise advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0322
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-762510.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762520.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762530.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762540.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762550.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762560.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762570.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762580.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762590.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762600.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Splunk Splunk Enterprise: Multiple vulnerabilitiescert-bund
- unknownSplunk Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Splunk products (20 August 2026)cert-fr-avis
- highCVE-2026-76355: In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the in…nvd
- highCVE-2026-76354: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not ho…nvd
- mediumCVE-2026-76353: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not ho…nvd
- highCVE-2026-76352: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not ho…nvd
- highCVE-2026-76351: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gate…nvd
- highCVE-2026-76350: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a ro…nvd
- mediumCVE-2026-76349: In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could …nvd
- lowCVE-2026-76348: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Spl…nvd
- mediumCVE-2026-76347: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gate…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21