CVE-2026-76266: Splunk upgrade script grants root via writable install content
Splunk Enterprise on Linux has a 7.7 High flaw (CWE-269): the root-privileged package maintainer script trusts installation content that the Splunk service account can write to. A local user with service-account access alters the files, and an admin upgrade then executes them as root. Affected versions are below 10.4.3, 10.2.7, 10.0.10 and 9.4.15.
- CVSS 7.7 High, CWE-269, vector AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
- Affects Splunk Enterprise on Linux below 10.4.3, 10.2.7, 10.0.10 and 9.4.15
- Installations upgraded only from tar archives are not affected
- Fix: 10.4.3, 10.2.7, 10.0.10 or 9.4.15; workaround is tar instead of package
Read next
Security