Splunk Enterprise <10.4.2 Priv Esc via Raw Config Endpoints
CVE-2026-76264 Published on October 7, 2026
Improper Authorization through the REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-76264 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-76264
Want to know whenever a new CVE is published for Splunk? stack.watch will email you.
Affected Versions
Splunk Enterprise:- Version 10.4 and below 10.4.2 is affected.
- Version 10.2 and below 10.2.6 is affected.
- Version 10.0 and below 10.0.10 is affected.
- Version 9.4 and below 9.4.15 is affected.