Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-1002 |
|
History
Wed, 07 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information. | |
| Title | Improper Access Control in Splunk Enterprise | |
| Weaknesses | CWE-284 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-10-07T20:46:37.805Z
Reserved: 2026-08-19T12:02:03.621Z
Link: CVE-2026-76281
No data.
Status : Received
Published: 2026-10-07T21:17:19.483
Modified: 2026-10-07T21:17:19.483
Link: CVE-2026-76281
No data.
OpenCVE Enrichment
No data.
Weaknesses