Local Privilege Escalation through Linux Package Upgrades in Splunk Enterprise
Summary
| CVE | CVE-2026-76266 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-07 21:17:17 UTC |
| Updated | 2026-10-09 04:18:12 UTC |
| Description | In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-system commands with root privileges. The vulnerability is possible because the Linux package maintainer script trusts existing Splunk Enterprise installation content when it performs upgrade operations with root privileges. The vulnerability requires an affected Linux package upgrade to occur after the local user modifies the installation. The local user should not be able to elevate privileges at will. |
Risk And Classification
Primary CVSS: v3.1 7.7 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
EPSS: 0.001240000 probability, percentile 0.018700000 (date 2026-10-08)
Problem Types: CWE-269 | CWE-269 The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.7 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.7 | HIGH | CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Splunk | Splunk Enterprise | affected 10.4 10.4.3 custom | Not specified |
| CNA | Splunk | Splunk Enterprise | affected 10.2 10.2.7 custom | Not specified |
| CNA | Splunk | Splunk Enterprise | affected 10.0 10.0.10 custom | Not specified |
| CNA | Splunk | Splunk Enterprise | affected 9.4 9.4.15 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| advisory.splunk.com/advisories/SVD-2026-1001 | [email protected] | advisory.splunk.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jean-Michel Remi Boudreau (en)
Additional Advisory Data
Solutions
CNA: Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.
Workarounds
CNA: Use a tar file instead of a Linux package to upgrade Splunk Enterprise. For more information see [Upgrade on UNIX](https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/10.4/upgrade-or-migrate-splunk-enterprise/upgrade-on-unix) in the Splunk documentation.