---
id: CVE-2026-76264
title: >-
  In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a
  user who does not hold the "admin" or "power" Splunk roles could create or
  edit scripted lookup definitions through raw configuration endpoints
summary: >-
  In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a
  user who does not hold the "admin" or "power" Splunk roles could create or
  edit scripted lookup definitions through raw configuration endpoints. The
  vulnerability…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
vendor: Splunk
product: Splunk Enterprise
affected:
  - enterprise >= 10.4 < 10.4.2
  - enterprise >= 10.2 < 10.2.6
  - enterprise >= 10.0 < 10.0.10
  - enterprise >= 9.4 < 9.4.15
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:17:17.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76264'
references:
  - url: 'https://advisory.splunk.com/advisories/SVD-2026-1001'
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T21:54:15.092Z'
---

## Overview

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
