In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager. This could affect system integrity and disrupt service. The vulnerability is possible because knowledge bundle delta processing does not restrict removal paths to the staging directory and the endpoint does not enforce the expected authorization boundary. For more information see Knowledge bundle replication overview (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/knowledge-bundle-replication/knowledge-bundle-replication-overview) in the Splunk documentation.
References
| Link | Resource |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0801 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-19 22:17
Updated : 2026-08-21 19:13
NVD link : CVE-2026-76353
Mitre link : CVE-2026-76353
CVE.ORG link : CVE-2026-76353
JSON object : View
Products Affected
splunk
- splunk
CWE
CWE-24
Path Traversal: '../filedir'
