Splunk Enterprise 10.4.3 Improper Neutralization Vulnerability
CVE-2026-76284 Published on October 7, 2026
Improper Neutralization in Splunk Enterprise
Improper Neutralization. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Vulnerability Analysis
CVE-2026-76284 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Improper Neutralization
The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.
Products Associated with CVE-2026-76284
Want to know whenever a new CVE is published for Splunk? stack.watch will email you.
Affected Versions
Splunk Enterprise:- Version 10.4 and below 10.4.3 is affected.
- Version 10.2 and below 10.2.7 is affected.
- Version 10.0 and below 10.0.10 is affected.
- Version 9.4 and below 9.4.15 is affected.