Sceawere

Vulnerability Detail

CVE-2026-76315UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Splunk Web Manager Configuration RCE

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Splunk
Product
Splunk Enterprise
Attack Type
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute arbitrary code on the Splunk platform instance through Splunk Web Manager Configuration. The user could then access all relevant data and affect system integrity and availability on the Splunk platform instance. The vulnerability is possible because Splunk Web Manager Configuration evaluates manager configuration values, and the Representational State Transfer (REST) API path for manager configuration does not require the permission that normally controls manager configuration writes. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) and restmap.conf (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/configuration-file-reference/10.2.0-configuration-file-reference/restmap.conf) in the Splunk documentation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-19T22:17:15.370Z",
  "pubdate": "2026-08-19T22:17:15.370Z",
  "executiveSummary": "Splunk Enterprise contains an arbitrary code execution vulnerability involving the Splunk Web Manager Configuration component. The flaw allows authenticated users who lack administrative or power roles to execute arbitrary code on the affected platform instance.\nThe vulnerability stems from improper authorization enforcement within the Representational State Transfer (REST) API path designated for manager configuration, which fails to require the permissions normally enforced for configuration write operations.\nSuccessful exploitation compromises system confidentiality, integrity, and availability by allowing unauthorized actors to access relevant data and execute arbitrary code on the platform instance.\nAffected products include Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14.\nAttackers require low-privileged user access to the Splunk platform instance to interact with the vulnerable REST API endpoints and trigger the insecure evaluation of manager configuration values.",
  "technicalDetails": "The root cause of the vulnerability resides in the authorization logic governing the Representational State Transfer (REST) API path associated with manager configuration in Splunk Enterprise.\nSpecifically, the REST endpoint responsible for handling manager configuration does not properly enforce the permission checks that normally control configuration write operations. As a result, low-privileged users who do not possess the \"admin\" or \"power\" Splunk roles can invoke these restricted endpoints.\nDuring the attack flow, a malicious user leverages the lack of proper privilege validation on the manager configuration REST API path. The user submits crafted requests containing manager configuration values to the endpoint.\nThe vulnerable component, Splunk Web Manager Configuration, evaluates these supplied configuration values. Because the evaluation process mishandles the input and the underlying API lacks adequate access controls, the application processes the untrusted configuration data in an insecure manner.\nThis improper evaluation allows the execution of arbitrary code within the context of the Splunk platform instance.\nThe vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14.\nAuthentication is required to interact with Splunk Web and the REST API, but the privilege requirements are bypassed due to the flawed authorization checks on the specific REST path, allowing standard users without administrative or power capabilities to exploit the flaw.\nPost-exploitation impact includes full system compromise, granting the attacker the ability to access all relevant data, manipulate system integrity, and disrupt availability on the targeted Splunk platform instance."
}
CVE-2026-76315: Splunk Web Manager Configuration RCE (HIGH Severity, CVSS: 8.8) - Sceawere