CVE-2026-76277
Last modified
CVE-2026-76277 is a medium-severity vulnerability rated 4.1/10 on the CVSS scale. In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/use-the-native-splunk-platform-authentication-scheme/set-up-native-splunk-authentication) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk Enterprise | >= 10.4, < 10.4.3; >= 10.2, < 10.2.7; >= 10.0, < 10.0.10; >= 9.4, < 9.4.15 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-76277?
How severe is CVE-2026-76277?
How do I fix CVE-2026-76277?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76271In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…6.5
- CVE-2026-76272In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…4.3
- CVE-2026-76273In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…4.3
- CVE-2026-76274In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…6.5
- CVE-2026-76275In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…4.3
- CVE-2026-76276In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…4.3
- CVE-2026-76278In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…4.3
- CVE-2026-76279In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…4.3
- CVE-2026-7628A vulnerability was detected in crazyrabbitLTC mcp-code-revi…6.3
- CVE-2026-76280In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…6.3
- CVE-2026-76281Improper Access Control. Splunk addressed multiple internall…5.3
- CVE-2026-76282Improper Control of a Resource Through its Lifetime. Splunk …8.8
Are you affected by CVE-2026-76277?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
