In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher. After upgrading, set `scripted_lookup_raw_write_enforcement = block` in the `limits.conf` configuration file under [lookup], and then restart Splunk Enterprise. For more information see [Configuration file reference](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/configuration-file-reference/10.2.7-configuration-file-reference/limits%2Econf) in the Splunk documentation.


Workaround

No workaround given by the vendor.

History

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.
Title Improper Authorization through the REST API in Splunk Enterprise
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:28.292Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:17.003

Modified: 2026-10-07T21:17:17.003

Link: CVE-2026-76264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses