← All Advisories

Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Dispatch Archive and Recover Session Tokens That Grant Access to All Data Available to the Report Owner

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-76310

Key Details

CVECVE-2026-76310
CVSS Score / Version9.4 (Critical) / CVSS v3.1
Updated2026-08-27
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is low.
Affected productsSplunk splunk
Classified asCWE-284 (Improper Access Control)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Splunksplunk
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk role. The vulnerability is possible because embedded report access does not block Representational State Transfer (REST) API dispatch archive download requests. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.1/report-management/additional-configuration-for-embedded-reports) and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation. (NVD)

What to Do

Monitor Splunk's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-76310
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-76310
Vendor advisoryhttps://advisory.splunk.com/advisories/SVD-2026-0801