CVE-2026-76337
Path Traversal through Splunk Web Static File Serving in Splunk Enterprise
Severity
Medium 5.3
CVSS 3.1
Exploited
Not listed
EPSS
0.003
22.7th percentile
Discovered by
Not disclosed
Published
Aug 19, 2026
Assigned by cisco
Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability is possible because Splunk Web does not restrict static file requests to the configured static directory.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Enterprise | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Splunk · Splunk Enterprise
Vendor remediation
Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.