Sceawere
Vulnerability Detail
CVE-2026-76312UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Splunk Enterprise Embedded Report Authorization Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.4
- Creation Date
- 2h ago
- Vendor
- Splunk
- Product
- Splunk Enterprise
- Attack Type
- The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system integrity. The vulnerability is possible because the dispatch archive download path does not correctly enforce the embedded-report authorization boundary and includes sensitive session material in archived search-job data. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.4",
"pubDate": "2026-08-19T22:17:14.960Z",
"pubdate": "2026-08-19T22:17:14.960Z",
"executiveSummary": "Splunk Enterprise contains an authorization boundary enforcement vulnerability within the dispatch archive download path for embedded reports. The flaw allows an unauthenticated attacker capable of reading the Hypertext Markup Language (HTML) source of a page embedding a Splunk report to extract sensitive session material. This exposed session material can subsequently be leveraged to access all relevant data and compromise system integrity. The vulnerability affects Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14. Risk implications include unauthorized data access and potential manipulation of system states, as the system fails to adequately segregate privileges or restrict access to archived search-job data associated with embedded reports. Exploitation requires the attacker to possess network access sufficient to view the HTML source of a page containing an embedded report, after which the exposed session credentials facilitate unauthorized interaction with the underlying Splunk instance.",
"technicalDetails": "The root cause of the vulnerability lies in the improper enforcement of the embedded-report authorization boundary within the dispatch archive download path. Specifically, when a Splunk report is embedded in an HTML page, the underlying mechanism fails to properly restrict access to dispatch artifacts and improperly includes sensitive session material directly within the archived search-job data. This design flaw exposes cryptographic or session tokens inside the DOM or source code accessible to viewers of the embedded report.\nThe affected component is the dispatch archive download subsystem responsible for packaging and serving search-job data for embedded reports. The vulnerability impacts Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14. No specialized privileges or prior authentication are strictly required from the perspective of the external observer; an unauthenticated user who simply has read access to the HTML source code of a page embedding a vulnerable Splunk report can extract the sensitive session material.\nThe attack flow proceeds as follows: First, an administrator or user embeds a Splunk report into a web page or application interface. Second, when the report is rendered, the dispatch archive download path generates or includes sensitive session material within the page's HTML source or associated downloadable dispatch archives without validating whether the requesting entity possesses the necessary administrative or viewing authorization for the underlying search job. Third, an unauthenticated attacker accesses the page containing the embedded report and inspects the Hypertext Markup Language (HTML) source code. Fourth, the attacker extracts the exposed session material from the source. Fifth, utilizing the harvested session material, the attacker issues unauthorized requests to the Splunk instance, bypassing standard authentication controls to access sensitive data associated with search jobs and potentially affecting overall system integrity."
}