← All Advisories

Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Search Job Dispatch Archive and Recover Session Material for Full Report Data Access

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-76311

Key Details

CVECVE-2026-76311
CVSS Score / Version9.4 (Critical) / CVSS v3.1
Updated2026-08-27
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is low.
Affected productsSplunk splunk
Classified asCWE-284 (Improper Access Control)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Splunksplunk
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible because the embedded report authorization flow does not block dispatch archive download requests before Splunk Enterprise begins sending the archive to the requester. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation. (NVD)

What to Do

Monitor Splunk's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-76311
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-76311
Vendor advisoryhttps://advisory.splunk.com/advisories/SVD-2026-0801