{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-76277","assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","state":"PUBLISHED","assignerShortName":"cisco","dateReserved":"2026-08-19T12:02:03.621Z","datePublished":"2026-10-07T20:46:35.907Z","dateUpdated":"2026-10-07T20:46:35.907Z"},"containers":{"cna":{"affected":[{"product":"Splunk Enterprise","vendor":"Splunk","versions":[{"version":"10.4","status":"affected","versionType":"custom","lessThan":"10.4.3"},{"version":"10.2","status":"affected","versionType":"custom","lessThan":"10.2.7"},{"version":"10.0","status":"affected","versionType":"custom","lessThan":"10.0.10"},{"version":"9.4","status":"affected","versionType":"custom","lessThan":"9.4.15"}],"modules":["REST API"]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/markdown","value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the `edit_user` capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see [Set up native Splunk authentication](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/use-the-native-splunk-platform-authentication-scheme/set-up-native-splunk-authentication) and [Define roles on the Splunk platform with capabilities](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation."}],"value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/use-the-native-splunk-platform-authentication-scheme/set-up-native-splunk-authentication) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation."}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001"}],"title":"Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterprise","datePublic":"2026-10-07T00:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","type":"cwe","cweId":"CWE-20","description":"The product does not validate or incorrectly validates input that can affect the control flow or data flow of a program."}]}],"source":{"advisory":"SVD-2026-1001","discovery":"INTERNAL"},"providerMetadata":{"orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco","dateUpdated":"2026-10-07T20:46:35.907Z"},"metrics":[{"cvssV3_1":{"vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L","version":"3.1","baseScore":4.1,"baseSeverity":"MEDIUM"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"solutions":[{"lang":"en","value":"Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher."}],"credits":[{"lang":"en","value":"Gabriel Nitu, Splunk","type":"finder"}]}}}