CVE-2026-76311Disclosure(splunk / splunk)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible because the embedded report authorization flow does not block dispatch archive download requests before Splunk Enterprise begins sending the archive to the requester. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
splunk

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-20: 1Technical Details · 2026-08-20: 108-20
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatAft@ThreatAft
    Disclosure

    🚨 Critical Splunk Enterprise flaws — CVE-2026-76310/11/12 CVSS 9.4 vulnerabilities affecting embedded report token handling could expose session material and potentially enable account takeover. 🔗 https://threataft.com/articles/splunk-enterprise-token-theft-embedded-report-flaws-cve-2026-76310-cve-2026-76311-cve-2026-76312?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #Splunk #CVE #InfoSec https://t.co/VGSS5VO9m9

    Post summary

    The tweet discloses critical Splunk Enterprise vulnerabilities (CVE-2026-76310/11/12) with a CVSS score of 9.4, highlighting potential session exposure and account takeover risks and linking to an article for further details.

    0000056
    37 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---

Explore more