CVE-2026-76312Disclosure(splunk / splunk)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system integrity. The vulnerability is possible because the dispatch archive download path does not correctly enforce the embedded-report authorization boundary and includes sensitive session material in archived search-job data. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
splunk

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-20: 1Technical Details · 2026-08-20: 108-20
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatAft@ThreatAft
    Disclosure

    🚨 Critical Splunk Enterprise flaws — CVE-2026-76310/11/12 CVSS 9.4 vulnerabilities affecting embedded report token handling could expose session material and potentially enable account takeover. 🔗 https://threataft.com/articles/splunk-enterprise-token-theft-embedded-report-flaws-cve-2026-76310-cve-2026-76311-cve-2026-76312?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #Splunk #CVE #InfoSec https://t.co/VGSS5VO9m9

    Post summary

    The tweet announces highly critical CVE‑2026‑76310/11/12, noting that embedded report token handling flaws could expose session data and enable account takeover.

    0000056
    37 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---
Appsplunksplunk10.4.0--

Explore more