CVE-2026-76269: Improper Access Control in Search Job Retrieval through the REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs that belong to other users, including search query text, job metadata, results, and preview results, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully validate job ownership before returning search job information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.10 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.15
Event History
Frequently Asked Questions
Which users can exploit this issue?
A user who does not have the Splunk "admin" or "power" role can exploit it. Exploitation requires access to the REST API and a user-controlled search job identifier.
What information could be exposed?
The issue can expose substantially all information associated with another user's search job, including the search query text, job metadata, results, and preview results. The reported impact is confidentiality only; integrity and availability are not affected.
Which Splunk Enterprise versions are affected?
Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are affected. Upgrading to the applicable listed version or later addresses the affected version ranges.
How can an organization determine whether it may be exposed?
Review whether users without the "admin" or "power" role can access the Splunk REST API and retrieve search-job data using identifiers for jobs owned by other users. Systems running a version below one of the listed fixed releases should be treated as affected.