CVE-2026-76310: Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise

Published Aug 19, 2026
·
Updated

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk role. The vulnerability is possible because embedded report access does not block Representational State Transfer (REST) API dispatch archive download requests. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.1/report-management/additional-configuration-for-embedded-reports) and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

Affected Software

1 affected component
Splunk Splunk Enterprise<10.4.2, =10.2.6, =10.0.9, =9.4.14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.4.2
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.2.6
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.9
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 9.4.14

Event History

Aug 19, 2026
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected when embedded reports are available and an attacker has an embedded report token. The resulting access is limited by the report owner’s data access and privileges, but can include administrative actions if that owner has the admin role.

2

What does an attacker need to exploit this issue?

The attacker does not need to authenticate, but must possess an embedded report token. They can use the token to download the associated search job dispatch archive through REST API requests and recover session material.

3

How can we assess the potential impact of an exposed embedded report?

Identify embedded reports and determine the Splunk role and data access assigned to each report owner. Reports owned by users with broad data access create broader exposure; reports owned by an admin-role user may allow administrative actions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203