CVE-2026-76259
published 2026-08-19CVE-2026-76259: In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the…
PriorityP347high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.7th percentile
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all relevant data and system integrity available to the user account running Splunk Enterprise. The vulnerability is possible because the Windows management-port listener does not apply exclusive address binding protections before the service starts.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| splunk | splunk | >= 10.0.0 < 10.0.9 | 10.0.9 |
| splunk | splunk | >= 10.2.0 < 10.2.6 | 10.2.6 |
| splunk | splunk | >= 10.4.0 < 10.4.2 | 10.4.2 |
| splunk | splunk | >= 9.3.0 < 9.3.14 | 9.3.14 |
| splunk | splunk | >= 9.4.0 < 9.4.13 | 9.4.13 |
| splunk | splunk_enterprise | >= 10.0 < 10.0.9 | 10.0.9 |
| splunk | splunk_enterprise | >= 10.2 < 10.2.6 | 10.2.6 |
| splunk | splunk_enterprise | >= 10.4 < 10.4.2 | 10.4.2 |
| splunk | splunk_enterprise | >= 9.3 < 9.3.14 | 9.3.14 |
| splunk | splunk_enterprise | >= 9.4 < 9.4.13 | 9.4.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise star
ghsa_unreviewed·2026-08-20
CVE-2026-76259 [HIGH] CWE-269 In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise star
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all relevant data and system integrity available to the user account running Splunk Enterprise. The vulnerability is possible because the Windows management-port listener does not apply exclusive address binding protections before the service starts.
VulDB
Splunk Enterprise up to 10.4.1 Management Port Listener privileges management
vuldb·2026-08-20·CVSS 8.8
CVE-2026-76259 [HIGH] Splunk Enterprise up to 10.4.1 Management Port Listener privileges management
A vulnerability, which was classified as very critical, was found in Splunk Enterprise up to 9.3.13/9.4.12/10.0.8/10.2.5/10.4.1. This vulnerability affects unknown code of the component Management Port Listener. The manipulation results in improper privilege management.
This vulnerability was named CVE-2026-76259. The attack needs to be approached locally. There is no available exploit.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published