{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-76284",
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "state": "PUBLISHED",
        "assignerShortName": "cisco",
        "dateReserved": "2026-08-19T12:02:03.621Z",
        "datePublished": "2026-10-07T20:46:39.281Z",
        "dateUpdated": "2026-10-07T20:46:39.281Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "product": "Splunk Enterprise",
                    "vendor": "Splunk",
                    "versions": [
                        {
                            "version": "10.4",
                            "status": "affected",
                            "versionType": "custom",
                            "lessThan": "10.4.3"
                        },
                        {
                            "version": "10.2",
                            "status": "affected",
                            "versionType": "custom",
                            "lessThan": "10.2.7"
                        },
                        {
                            "version": "10.0",
                            "status": "affected",
                            "versionType": "custom",
                            "lessThan": "10.0.10"
                        },
                        {
                            "version": "9.4",
                            "status": "affected",
                            "versionType": "custom",
                            "lessThan": "9.4.15"
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/markdown",
                            "value": "Improper Neutralization. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information."
                        }
                    ],
                    "value": "Improper Neutralization. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information."
                }
            ],
            "references": [
                {
                    "url": "https://advisory.splunk.com/advisories/SVD-2026-1002"
                }
            ],
            "title": "Improper Neutralization in Splunk Enterprise",
            "datePublic": "2026-10-07T00:00:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "type": "cwe",
                            "cweId": "CWE-707",
                            "description": "The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties at met before being read from an upstream component or sent to a downstream component."
                        }
                    ]
                }
            ],
            "source": {
                "advisory": "SVD-2026-1002",
                "discovery": "INTERNAL"
            },
            "providerMetadata": {
                "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
                "shortName": "cisco",
                "dateUpdated": "2026-10-07T20:46:39.281Z"
            },
            "solutions": [
                {
                    "lang": "en",
                    "value": "Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher."
                }
            ]
        }
    }
}