CVE-2026-76277: Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edituser capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/use-the-native-splunk-platform-authentication-scheme/set-up-native-splunk-authentication) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.10 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.15
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Splunk Enterprise user must hold a role with the edit_user capability. The attack complexity is high, and no user interaction is required.
Which deployments are affected?
Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are affected. The issue concerns native Splunk usernames created through the REST API.
What is the practical impact?
A username ending in a period can share per-user configuration data with a distinct native username. User-management operations may then affect the wrong account or fail, with potential confidentiality, integrity, and availability impact.
How can administrators identify potential exposure?
Review native Splunk accounts, particularly those created through the REST API, for usernames ending in a period. Such accounts are the condition described as allowing per-user directory collisions.