What CVE-2026-76266 shows about trusting installation content in package scripts
Software maintainers write install and upgrade scripts that run with more privilege than the application they manage. CVE-2026-76266 is a worked example of what happens when such a script reads state the application account controls.
Vulnerability overview
The flaw affects Splunk Enterprise on Linux and is rated 7.7 High, CWE-269, vector CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H. Splunk documents it in SVD-2026-1001, and NCSC-2026-0412 carries the same score.
The trust assumption, stated plainly
The vendor advisory says the Linux package maintainer script trusts existing Splunk Enterprise installation content when it performs upgrade operations with root privileges. The service account that runs Splunk Enterprise can write to that content. Privilege and writability therefore cross in the middle of an upgrade.
Mechanism and exploitation conditions
A local user who can run commands as the Splunk service account modifies the installation content, recorded as PR:H. An administrator then triggers an affected Linux package upgrade, recorded as UI:R, and the altered content executes as root. The advisory states the local user should not be able to elevate privileges at will, so the design intent was that this sequence stay closed.
Impact
Root on the host, with high confidentiality, integrity and availability impact, including indexed data, stored collection credentials and the operating system.
Affected products and scope
Splunk Enterprise on Linux, below 10.4.3, 10.2.7, 10.0.10 and 9.4.15, with ranges 10.4.0 to 10.4.2, 10.2.0 to 10.2.6, 10.0.0 to 10.0.9 and 9.4.0 to 9.4.14. Installations upgraded only from tar archives avoid the vulnerable maintainer script. No exploitation in the wild is reported.
Remediation and mitigations
Patch to 10.4.3, 10.2.7, 10.0.10 or 9.4.15, or higher. If an upgrade is needed before patching, use a tar file instead of a Linux package, which is Splunk's documented workaround. For anyone shipping packages, the transferable check is simple to run and worth running: list every root-privileged install and upgrade step and confirm it does not read files writable by the account it manages.
References
- Splunk advisory SVD-2026-1001, https://advisory.splunk.com/advisories/SVD-2026-1001
- NCSC-2026-0412, https://advisories.ncsc.nl/2026/ncsc-2026-0412.html
Top comments (0)