CVE-2026-76310Disclosure(splunk / splunk)

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch splunk splunk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk role. The vulnerability is possible because embedded report access does not block Representational State Transfer (REST) API dispatch archive download requests. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.1/report-management/additional-configuration-for-embedded-reports) and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
splunk

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-20: 2Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-20: 108-20
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vistem Solutions@VistemSolutions
    Patch

    NVD - CVE-2026-76310 Official websites use .gov — and when it comes to cybersecurity alerts, trusted sources matter. If your organization is reviewing CVE-2026-76310, take action now: ✅ Verify whether your systems are affected ✅ Review vendor guidance and official NVD details ✅ Prioritize patching or mitigation based on risk ✅ Document remediation steps for compliance ✅ Monitor for updates as new details become available Cybersecurity isn’t just about reacting to vulnerabilities — it’s about building a secure, resilient business. Vistem Solutions helps organizations strengthen security, reduce risk, and stay prepared with outcome-driven cybersecurity and IT expertise. 📩 Ready to elevate your security strategy? Contact us: sales@vistem.com #VistemSolutions #VistemElevate #Cybersecurity #CyberResilience #CVE #VulnerabilityManagement #SecurityCompliance #ITSecurity #BusinessSecurity #SecureInnovation #MSPExpertise https://nvd.nist.gov/vuln/detail/CVE-2026-76310?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer

    Post summary

    The post advises organizations to review CVE‑2026‑76310 and apply vendor guidance or patches, but it lacks technical details or exploit information.

    0000022
    86 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 Critical Splunk Enterprise flaws — CVE-2026-76310/11/12 CVSS 9.4 vulnerabilities affecting embedded report token handling could expose session material and potentially enable account takeover. 🔗 https://threataft.com/articles/splunk-enterprise-token-theft-embedded-report-flaws-cve-2026-76310-cve-2026-76311-cve-2026-76312?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #Splunk #CVE #InfoSec https://t.co/VGSS5VO9m9

    Post summary

    The tweet announces critical Splunk Enterprise CVEs (2026‑76310/11/12) with high severity and potential account takeover, but does not provide proof‑of‑concepts, exploits, or patch information.

    0000056
    37 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---

Explore more