Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-76284: Splunk Enterprise may allow unauthorized code execution

CVE-2026-76284 · published 2 days ago
Summary

Some older versions of Splunk Enterprise (10.4.3, 10.2.7, 10.0.10, and 9.4.15) contain a weakness that could let a remote user send specially crafted data that the system does not handle correctly. This could allow the attacker to run their own code on the server, possibly exposing business data or disrupting operations. Upgrade to the latest Splunk Enterprise release or apply the security patches provided by Splunk as soon as possible.

What to do
  • Update splunk splunk enterprise to version 10.4.3 or later.
Affected software
VendorProductAffected versions
splunk splunk enterprise < 10.4.3
Original advisory text
Improper Neutralization in Splunk Enterprise
Improper Neutralization. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-707Improper Neutralization
Timeline
Published7 Oct 2026
Updated10 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-76284 · MITRE
Track software like this
Free during beta