CVE-2026-76264

Improper Authorization through the REST API in Splunk Enterprise

Severity
Medium 4.3
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
—
Discovered by
Not disclosed
Published
Oct 7, 2026
Assigned by cisco

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.

Weakness: CWE-863

Affected products

Vendor Product Category Matched by
Cisco Splunk Enterprise SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Splunk · Splunk Enterprise

Credit

M Mahdan Argya Syarif (0xbeludan)

Vendor remediation

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher. After upgrading, set `scripted_lookup_raw_write_enforcement = block` in the `limits.conf` configuration file under [lookup], and then restart Splunk Enterprise. For more information see [Configuration file reference](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/configuration-file-reference/10.2.7-configuration-file-reference/limits%2Econf) in the Splunk documentation.

Something wrong here?