chiprook
← Security
SecurityOctober 10, 2026, 12:00

CVE-2026-76266: Splunk upgrade script grants root via writable install content

Splunk Enterprise on Linux has a 7.7 High flaw (CWE-269): the root-privileged package maintainer script trusts installation content that the Splunk service account can write to. A local user with service-account access alters the files, and an admin upgrade then executes them as root. Affected versions are below 10.4.3, 10.2.7, 10.0.10 and 9.4.15.

CVE-2026-76266: Splunk upgrade script grants root via writable install content
#Splunk
Read next
Security

Malicious npm packages evade install-script defenses at runtime

Security

CVE-2026-31431: 732-byte exploit grants root on Linux

Security

CVE-2026-76461: SQL injection in Cisco email gateway grants root

Security

OnePlus flaws let installed apps gain root without permissions