What is CVE-2026-76336?
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user without "admin" or "power" roles can delete all SPL2 modules across all apps and users via the SPL2 module management REST API. This vulnerability allows a low-privileged user to remove critical search processing modules. Affected users should immediately upgrade to versions 10.4.2, 10.2.6, or later.
Azərbaycanca: Splunk Enterprise-in 10.4.2 və 10.2.6-dan aşağı versiyalarında, "admin" və ya "power" roluna malik olmayan istifadəçi SPL2 modul idarəetmə REST API-si vasitəsilə bütün istifadəçi və tətbiqlərin SPL2 modullarını silə bilər. Zəiflik aşağı imtiyazlı istifadəçiyə kritik axtarış modullarını silmək imkanı verir. Splunk Enterprise istifadəçiləri dərhal 10.4.2, 10.2.6 və ya daha yuxarı versiyalara yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Splunk
FAQ2
Which privileged users are affected by CVE-2026-76336 in Splunk Enterprise?
This vulnerability affects users without "admin" or "power" roles, meaning low-privileged users.
To which versions should Splunk Enterprise users upgrade to protect against CVE-2026-76336?
Users should immediately upgrade to versions 10.4.2, 10.2.6, or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.