CVE-2026-76278: Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise

Published Oct 7, 2026
·
Updated

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the editspl2modulepermissions capability could use the affected Representational State Transfer (REST) API to access permission grants for SPL2 modules that the user does not have permission to view. The vulnerability is possible because Splunk Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. For more information see Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) and Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) in the Splunk documentation.

Splunk Enterprise versions 9.4.x are not affected.

Affected Software

1 affected component
Splunk Splunk Enterprise<10.4.3, <10.2.7, <10.0.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.4.3
  2. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.2.7
  3. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.0.10
  4. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 9.4.15

Event History

Oct 7, 2026
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user must hold a role with the edit_spl2_module_permissions capability. The issue is exposed through the affected REST API.

2

What information could an attacker obtain?

The attacker could access permission grants for SPL2 modules in apps that they do not have permission to view. The provided data describes an information-disclosure impact only, with no integrity or availability impact.

3

Which versions are affected and which are fixed?

Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 are affected. Splunk Enterprise 9.4.x is not affected.

4

What condition enables the authorization bypass?

The affected REST API returns SPL2 module permission grants without verifying that the requesting user can read the requested app.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203