What is CVE-2026-76348?
In affected Splunk Enterprise versions, a user with the high-privilege list_search_head_clustering capability can change the cluster state via read requests to Search Head Cluster control endpoints, potentially causing a denial of service. Affected versions are those below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Administrators should upgrade to the specified versions immediately.
Azərbaycanca: Splunk Enterprise-in müəyyən versiyalarında list_search_head_clustering imtiyazına malik istifadəçi Search Head Cluster idarəetmə endpoint-lərinə oxuma sorğusu göndərərək klaster vəziyyətini dəyişə bilər, bu da xidmətin pozulmasına (denial of service) səbəb ola bilər. Təsirə məruz qalan versiyalar 10.4.2, 10.2.6, 10.0.9 və 9.4.14-dən aşağı olanlardır. Sistem inzibatçıları dərhal göstərilən versiyalara yüksəltmə aparmalıdırlar.
Related CVEs
link basis: shared vendor: Splunk
FAQ2
Which component of Splunk Enterprise does CVE-2026-76348 affect?
This vulnerability affects the Search Head Cluster control endpoints.
What should administrators do to resolve this issue?
Administrators should immediately upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, 9.4.14 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.