CVE-2026-76336
published 2026-08-19CVE-2026-76336: In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language…
PriorityP342high7.1CVSS 3.1
AVNACLPRLUINSUCNIHAL
EPSS
0.24%
14.8th percentile
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service disruption. The vulnerability does not affect Splunk Enterprise versions below 10.2. The vulnerability is possible because the SPL2 module management REST API does not sufficiently authorize and validate module deletion requests. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| splunk | splunk | >= 10.2.0 < 10.2.6 | 10.2.6 |
| splunk | splunk | >= 10.4.0 < 10.4.2 | 10.4.2 |
| splunk | splunk_enterprise | >= 10.2 < 10.2.6 | 10.2.6 |
| splunk | splunk_enterprise | >= 10.4 < 10.4.2 | 10.4.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and use
ghsa_unreviewed·2026-08-20
CVE-2026-76336 [HIGH] CWE-862 In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and use
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service disruption. The vulnerability does not affect Splunk Enterprise versions below 10.2. The vulnerability is possible because the SPL2 module management REST API does not sufficiently authorize and validate module deletion requests. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modul
VulDB
Splunk Enterprise up to 10.2.5/10.4.1 SPL2 module management REST API privileges management
vuldb·2026-08-20·CVSS 7.1
CVE-2026-76336 [HIGH] Splunk Enterprise up to 10.2.5/10.4.1 SPL2 module management REST API privileges management
A vulnerability was found in Splunk Enterprise up to 10.2.5/10.4.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component SPL2 module management REST API. The manipulation leads to improper privilege management.
This vulnerability is listed as CVE-2026-76336. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published