What is CVE-2026-76344?
CVE-2026-76344 allows a low-privileged Splunk Enterprise user without 'admin' or 'power' roles to write dispatch metadata to an arbitrary location on the host via a crafted search identifier through a REST API endpoint. This affects versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and upgrading to these versions is required to mitigate the risk.
Azərbaycanca: CVE-2026-76344 Splunk Enterprise-in 10.4.2, 10.2.6, 10.0.9 və 9.4.14 versiyalarından aşağı olanlarda aşağı səlahiyyətli istifadəçiyə (admin/power rolu olmayan) xüsusi hazırlanmış axtarış identifikatoru ilə REST API endpoint-i vasitəsilə hostda ixtiyari dispatch metadata faylı yazmağa imkan verir. Bu boşluq məlumatın bütövlüyünü poza bilər, ona görə də sürətlə göstərilən versiyalara patch tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Splunk
FAQ2
Which versions of Splunk Enterprise are affected by CVE-2026-76344?
This vulnerability affects all versions of Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
What can an attacker achieve on the host by exploiting CVE-2026-76344?
The attacker can write dispatch metadata files to an arbitrary location on the host, which may compromise data integrity.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.