Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0801 |
|
Thu, 20 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Splunk
Splunk splunk Enterprise |
|
| Vendors & Products |
Splunk
Splunk splunk Enterprise |
Wed, 19 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager. This could affect system integrity and disrupt service. The vulnerability is possible because knowledge bundle delta processing does not restrict removal paths to the staging directory and the endpoint does not enforce the expected authorization boundary. For more information see Knowledge bundle replication overview (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/knowledge-bundle-replication/knowledge-bundle-replication-overview) in the Splunk documentation. | |
| Title | Path Traversal through Knowledge Bundle Replication in Splunk Enterprise | |
| Weaknesses | CWE-24 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-08-19T21:34:46.696Z
Reserved: 2026-08-19T12:02:03.628Z
Link: CVE-2026-76353
No data.
Status : Received
Published: 2026-08-19T22:17:20.340
Modified: 2026-08-19T22:17:20.340
Link: CVE-2026-76353
No data.
OpenCVE Enrichment
Updated: 2026-08-20T00:00:05Z
-
CWE-24
Path Traversal: '../filedir'