Medium severity5.3NVD Advisory· Published Aug 19, 2026· Updated Aug 26, 2026
CVE-2026-76337
CVE-2026-76337
Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability is possible because Splunk Web does not restrict static file requests to the configured static directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <10.4.2, <10.2.6, <10.0.9, <9.4.14
Patches
Vulnerability mechanics
References
1- advisory.splunk.com/advisories/SVD-2026-0801nvdVendor Advisory
News mentions
1- Splunk Enterprise: 25 Vulnerabilities Disclosed Together, Affecting Multiple VersionsVypr Intelligence · Aug 19, 2026