deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

CVE-2026-76266: Splunk Linux package upgrades can run service-account files as root

Splunk patched CVE-2026-76266, a 7.7-rated flaw where Linux package upgrade scripts trust installation files writable by the Splunk service account, allowing modified content to execute as root during admin-run upgrades.

CVE-2026-76266: Splunk Linux package upgrades can run service-account files as root

What happened

Splunk has released patches for CVE-2026-76266, a high-severity privilege escalation affecting Splunk Enterprise on Linux. According to a write-up on dev.to, the vulnerability carries a CVSS:3.1 score of 7.7, with vector AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H, and is classified under CWE-269, improper privilege management. Splunk documents the issue in advisory SVD-2026-1001, and the NCSC advisory NCSC-2026-0412 lists the same rating.

The trust assumption at the core

The bug lives in the Linux package maintainer script, the code a package manager runs as root while installing or upgrading the product. According to the dev.to analysis, that script trusts the existing Splunk Enterprise installation content on disk when it performs upgrade operations. The problem is that the service account running Splunk Enterprise can write to that same content. A file the service account controls is therefore consumed by a process running as root, and the two intersect exactly at the point of an upgrade.

How exploitation works

The attack requires two conditions, both visible in the CVSS vector.

First, the attacker must already be able to run commands as the Splunk service account, the PR:H prerequisite. That level of access allows them to modify files inside the installation content.

Second, an administrator has to trigger an upgrade using an affected Linux package, the UI:R requirement. When the maintainer script runs, it processes the tampered content with root privileges, and the attacker's modifications execute as root.

The dev.to piece notes that the advisory is explicit about design intent: a local user of this kind should not be able to elevate privileges at will. The expectation was that this sequence stayed closed, and the patched releases close it.

Impact

Successful exploitation yields root on the host, with high ratings across confidentiality, integrity and availability. The blast radius reaches beyond the operating system to Splunk's indexed data and stored collection credentials, which on a log aggregation platform are often among the most sensitive material on the machine.

Affected versions and remediation

According to the source, the vulnerable ranges are:

  • 10.4.0 through 10.4.2
  • 10.2.0 through 10.2.6
  • 10.0.0 through 10.0.9
  • 9.4.0 through 9.4.14

Fixed releases are 10.4.3, 10.2.7, 10.0.10 and 9.4.15, and administrators should upgrade to the relevant version or later. For sites that need to upgrade before they can patch, Splunk's documented workaround is to upgrade from a tar archive rather than a Linux package; installations handled only via tar never run the vulnerable maintainer script. No exploitation in the wild has been reported.

Why it matters

This is a template bug, not a Splunk quirk. Anyone shipping deb or rpm packages, container entrypoints, CI hooks, or any installer that runs with elevated privileges should borrow the audit the dev.to author proposes: enumerate every install or upgrade step that runs as root, then check whether any of those steps read files writable by the account the package manages. If the answer is yes, the upgrade path doubles as a privilege escalation bridge, and the fix belongs in the packaging rather than in documentation.

For Splunk deployments specifically, the preconditions are ordinary events rather than exotic ones: command execution as the service account combined with a routine admin-initiated upgrade. The patch is available now, and the tar-based workaround is a cheap stopgap for anyone caught between versions.

  • #security
  • #splunk
  • #vulnerability
  • #linux
  • #packaging

Related posts