Splunk Linux Upgrade Flaw Allows Local Privilege Escalation
A high-severity vulnerability, CVE-2026-76266, affects Splunk Enterprise on Linux. The flaw exists in the package maintainer's upgrade script, which runs with root privileges but reads from installation content the Splunk service account can modify. If a local user gains access as the service account, they can alter this content. When an administrator performs a Linux package upgrade, the malicious content then executes with full root privileges. The vulnerability impacts versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in