CVE-2026-76277
EUVD-2026-9462907.10.2026, 21:17
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/use-the-native-splunk-platform-authentication-scheme/set-up-native-splunk-authentication) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| splunk | splunk | 10.4 ≤ 𝑥 < 10.4.3 | CNA |
| splunk | splunk | 10.2 ≤ 𝑥 < 10.2.7 | CNA |
| splunk | splunk | 10.0 ≤ 𝑥 < 10.0.10 | CNA |
| splunk | splunk | 9.4 ≤ 𝑥 < 9.4.15 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure