CVE-2026-76348

⚪ Do wiadomości

Błąd w Splunk Enterprise umożliwia zmianę stanu klastra, co prowadzi do odmowy usługi.

CVSS
3.8
EPSS
0.2%
Exploit
none
Vendor
splunk
Opis źródłowy (NVD)

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Cluster member control endpoints and change cluster state, which could allow for a denial of service. The vulnerability is possible because the Search Head Cluster member control endpoints do not require a state-changing Hypertext Transfer Protocol (HTTP) request type before they apply read-only authorization.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-19 22:17:19 UTC
Ostatnia modyfikacja (NVD)2026-08-21 19:14:31 UTC
Referencje