CVE-2026-76281
Improper Access Control in Splunk Enterprise
Severity
Unscored
CVSS —
Exploited
Not listed
EPSS
—
Discovered by
Vendor
Vendor-published field
Published
Oct 7, 2026
Assigned by cisco
Description
Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Weakness: CWE-284
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Enterprise | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Splunk · Splunk Enterprise
Vendor remediation
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.