---
id: CVE-2026-76281
title: Improper Access Control
summary: >-
  Improper Access Control. Splunk addressed multiple internally identified
  vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and
  9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE),
  with one Co…
severity: none
cwe:
  - CWE-284
vendor: Splunk
product: Splunk Enterprise
affected:
  - enterprise >= 10.4 < 10.4.3
  - enterprise >= 10.2 < 10.2.7
  - enterprise >= 10.0 < 10.0.10
  - enterprise >= 9.4 < 9.4.15
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:17:19.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76281'
references:
  - url: 'https://advisory.splunk.com/advisories/SVD-2026-1002'
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T21:54:15.097Z'
---

## Overview

Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
