VDB
GCVE-110-NCSC-2026-322
GCVE-110-NCSC-2026-322
Advisory PublishedCVSS 8.1/10
Certain versions of Splunk Enterprise prior to 10.4.1, 10.2.6, 10.0.9, and 9.4.14 contain a vulnerability in the dispatch archive download path allowing unauthenticated users to access sensitive session data via embedded reports.
Weaknesses (CWE)
CWE-862Missing AuthorizationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-943Improper Neutralization of Special Elements in Data Query LogicCWE-321Use of Hard-coded Cryptographic KeyCWE-732Incorrect Permission Assignment for Critical ResourceCWE-639Authorization Bypass Through User-Controlled KeyCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-94Improper Control of Generation of Code ('Code Injection')CWE-26Path Traversal: '/dir/../filename'CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-352Cross-Site Request Forgery (CSRF)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-863Incorrect AuthorizationCWE-27Path Traversal: 'dir/../../filename'CWE-918Server-Side Request Forgery (SSRF)CWE-24Path Traversal: '../filedir'CWE-158Improper Neutralization of Null Byte or NUL CharacterCWE-306Missing Authentication for Critical Function
Risk Scores
CVSS 3.1
8.1/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Splunk | vers:unknown/* | — | — |
Aliases
CVE-2026-76251CVE-2026-76252CVE-2026-76253CVE-2026-76254CVE-2026-76255CVE-2026-76256CVE-2026-76257CVE-2026-76258CVE-2026-76259CVE-2026-76260CVE-2026-76261CVE-2026-76262CVE-2026-76263CVE-2026-76309CVE-2026-76310CVE-2026-76311CVE-2026-76312CVE-2026-76313CVE-2026-76314CVE-2026-76315CVE-2026-76316CVE-2026-76317CVE-2026-76318CVE-2026-76319CVE-2026-76320CVE-2026-76321CVE-2026-76322CVE-2026-76323CVE-2026-76324CVE-2026-76325CVE-2026-76326CVE-2026-76327CVE-2026-76328CVE-2026-76329CVE-2026-76330CVE-2026-76331CVE-2026-76332CVE-2026-76333CVE-2026-76334CVE-2026-76335CVE-2026-76336CVE-2026-76337CVE-2026-76338CVE-2026-76339CVE-2026-76340CVE-2026-76341CVE-2026-76342CVE-2026-76343CVE-2026-76344CVE-2026-76345CVE-2026-76346CVE-2026-76347CVE-2026-76348CVE-2026-76349CVE-2026-76350CVE-2026-76351CVE-2026-76352CVE-2026-76353CVE-2026-76354CVE-2026-76355
References
Browse GCVE Records
417 records in the GCVE database · Updated August 26, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.