What is CVE-2026-76352?
CVE-2026-76352 is a vulnerability in specific versions of Splunk Enterprise that allows a user without "admin" or "power" roles to create or modify a scripted lookup via generic configuration endpoints. This can enable an attacker to execute an installed lookup script with the permissions of the Splunk service account, potentially leading to privilege escalation. Upgrading affected versions to the latest security patches is strongly recommended.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Splunk
FAQ2
What specific roles are not required for an attacker to exploit CVE-2026-76352 in Splunk Enterprise?
The attacker does not require "admin" or "power" roles to exploit this vulnerability; they can act as a low-privileged user.
What can successful exploitation of CVE-2026-76352 lead to?
Successful exploitation can allow an attacker to execute an installed lookup script with the permissions of the Splunk service account, potentially leading to privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.