Back to database
Track29Medium5.3VulnerabilityCVE-2026-76281No patch link observed

CVE-2026-76281 — Improper Access Control.

Published Oct 7, 2026, 09:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-76281

Description

Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

Low

Confidentiality

I

None

Integrity

A

None

Availability