CVE-2026-76319Patch(splunk / splunk)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk splunk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution through Federated Search bundle selection. This could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Federated Search dispatch flow accepts caller-controlled bundle selection without enforcing the capability that manages federated providers and indexes. For more information see Security models for Federated Search for Splunk (https://help.splunk.com/en/splunk-enterprise/search/federated-search/10.4/run-federated-searches-across-other-splunk-deployments/service-accounts-and-security-for-federated-search-for-splunk/security-models-for-federated-search-for-splunk) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
splunk

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-20: 1Patch / Workaround · 2026-08-20: 108-20
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • MalwareObserver@MalwareObserver
    Patch

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-76319](https://advisory.splunk.com/advisories/SVD-2026-0801) In Splunk Enterprise versi... https://advisory.splunk.com/advisories/SVD-2026-0801 #CVE #ZeroDay #PatchManagement

    Post summary

    The tweet announces the zero‑day CVE‑2026‑76319 in Splunk Enterprise and references a vendor advisory that presumably contains a patch, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    0000024
    28 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---

Explore more