CVE-2026-76310 -- CVSS 9.4 Vulnerability Briefing
CVE-2026-76310 | CVSS 9.4 (Critical) | Exploit: PoC available
What Is It
CVE-2026-76310 is an authentication bypass and session-material exposure vulnerability in Splunk Enterprise embedded reports that affects versions earlier than 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
Technical Detail
An unauthenticated attacker who possesses an embedded report token can download the associated search job dispatch archive because embedded report access does not adequately restrict access to relevant REST functionality. The archive may contain session material that can be recovered and used to access data available to the report owner. This can result in privilege escalation to the report owner's effective permissions and may permit administrative actions when the report owner has the Splunk admin role.
Exploitation Status
A proof of concept is available. CVE-2026-76310 is not listed in CISA's Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed by CISA.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, 9.4.14, or a later supported release as a high-priority action. Until upgrades are complete, restrict or disable public embedded reports where operationally feasible, limit distribution of embedded report tokens, and review whether report owners have unnecessary administrative privileges. Review Splunk and reverse-proxy access logs for unauthenticated or unexpected requests involving embedded reports and search job dispatch archives, then investigate subsequent use of report-owner sessions, unusual data access, configuration changes, and administrative activity.