CVE-2026-76277

Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterprise

Severity
Medium 4.1
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
—
Discovered by
Vendor
Vendor-published field
Published
Oct 7, 2026
Assigned by cisco

Description

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/use-the-native-splunk-platform-authentication-scheme/set-up-native-splunk-authentication) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Cisco Splunk Enterprise SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Splunk · Splunk Enterprise

Credit

Gabriel Nitu, Splunk

Vendor remediation

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.

Something wrong here?