CVE-2026-76353: Path Traversal through Knowledge Bundle Replication in Splunk Enterprise

Published Aug 19, 2026
·
Updated

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager. This could affect system integrity and disrupt service. The vulnerability is possible because knowledge bundle delta processing does not restrict removal paths to the staging directory and the endpoint does not enforce the expected authorization boundary. For more information see Knowledge bundle replication overview (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/knowledge-bundle-replication/knowledge-bundle-replication-overview) in the Splunk documentation.

Affected Software

1 affected component
Splunk Splunk Enterprise<10.4.2, <10.2.6, <10.0.9, <9.4.14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.4.2
  2. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.2.6
  3. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.0.9
  4. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 9.4.14

Event History

Aug 19, 2026
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected where a cluster manager processes knowledge bundle delta submissions. The impact is deletion of files accessible to Splunk Enterprise on the cluster manager.

2

What access does an attacker need?

An attacker needs Splunk access sufficient to submit a crafted knowledge bundle delta. The issue specifically affects users who do not have the admin or power roles, because the endpoint does not enforce the expected authorization boundary.

3

What can an attacker do with successful exploitation?

A successful attacker can use crafted removal paths to delete arbitrary files that are accessible to the Splunk Enterprise process on the cluster manager. This can compromise system integrity and disrupt service.

4

Which versions contain the fix?

The fixed versions are 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Deployments running versions below the applicable fixed release should be considered affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203