← All Advisories

Splunk Enterprise Knowledge Bundle Upload Endpoint Lacks the edit_dist_peer Capability Check, Allowing Low-Privilege Users to Achieve Remote Code Execution via Distributed Search

Last refreshed2026-09-29

Status: UPDATED  |  Advisory ID: CVE-2026-76313

Key Details

CVECVE-2026-76313
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-08-27
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSplunk splunk
Classified asCWE-284 (Improper Access Control)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Splunksplunk
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Representational State Transfer (REST) API endpoint for knowledge bundle upload does not require the high-privilege capability edit_dist_peer, and distributed search accepts caller-supplied knowledge bundle selections from users who do not hold that capability. For more information see What search heads send to search peers (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.2/knowledge-bundle-replication/what-search-heads-send-to-search-peers), About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.0/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.1/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Using the REST API reference (https://help.splunk.com/en/splunk-enterprise/rest-api-reference/10.4/introduction/using-the-rest-api-reference) in the Splunk documentation. (NVD)

What to Do

Monitor Splunk's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-76313
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-76313
Vendor advisoryhttps://advisory.splunk.com/advisories/SVD-2026-0801