Jump to the main content block

【Vulnerability Alert】Splunk Enterprise Contains Multiple High-Risk Security Vulnerabilities. Please Confirm and Apply Patches as Soon as Possible

publish date : 2026-09-11 update date : 2026-09-11

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026090409092424 Publication Time 2026-09-04 09:12:32
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-04 09:12:32
Impact Level Medium  
[Subject]
【Vulnerability Alert】Splunk Enterprise Contains Multiple High-Risk Security Vulnerabilities. Please Confirm and Apply Patches as Soon as Possible
[Content]

Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202609-00000006

Researchers discovered that Splunk Enterprise contains multiple high-risk security vulnerabilities (CVE-2026-76253, CVE-2026-76310 to CVE-2026-76317, CVE-2026-76319, CVE-2026-76335, and CVE-2026-76350 to CVE-2026-76352). The most severe vulnerability, CVE-2026-76310, is an Improper Access Control vulnerability. If an unauthenticated remote attacker possesses an embedded report token (Token), the attacker may download the dispatch archive file of the associated search job and obtain session-related information from it, thereby accessing data that the report owner is authorized to access and affecting system integrity. If the report owner has the admin role, the attacker may even perform administrative operations. Please confirm and apply patches as soon as possible.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

Splunk Enterprise versions 9.4.0 to 9.4.13, 10.0.0 to 10.0.8, 10.2.0 to 10.2.5, and 10.4.0 to 10.4.1

[Recommended Actions]

The official vendor has released patches for the vulnerabilities. Please upgrade Splunk Enterprise to version 9.4.14, 10.0.9, 10.26, or 10.4.2 or later. For detailed information, please refer to the official advisory. The URL is as follows: https://advisory.splunk.com/advisories/SVD-2026-0801

[Reference]

1. https://nvd.nist.gov/vuln/detail/CVE-2026-76253
2. https://nvd.nist.gov/vuln/detail/CVE-2026-76310
3. https://nvd.nist.gov/vuln/detail/CVE-2026-76311
4. https://nvd.nist.gov/vuln/detail/CVE-2026-76312
5. https://nvd.nist.gov/vuln/detail/CVE-2026-76313
6. https://nvd.nist.gov/vuln/detail/CVE-2026-76314
7. https://nvd.nist.gov/vuln/detail/CVE-2026-76315
8. https://nvd.nist.gov/vuln/detail/CVE-2026-76316
9. https://nvd.nist.gov/vuln/detail/CVE-2026-76317
10. https://nvd.nist.gov/vuln/detail/CVE-2026-76319
11. https://nvd.nist.gov/vuln/detail/CVE-2026-76335
12. https://nvd.nist.gov/vuln/detail/CVE-2026-76350
13. https://nvd.nist.gov/vuln/detail/CVE-2026-76351
14. https://nvd.nist.gov/vuln/detail/CVE-2026-76352
15. https://advisory.splunk.com/advisories/SVD-2026-0801

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: