Splunk Enterprise for Windows Local Privilege Escalation Vulnerability (CVE-2026-76259)

Release Date: 31st August 2026 (Added 1 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate Splunk Enterprise on Windows hosts. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-76259 is a local privilege escalation vulnerability in Splunk Enterprise for Windows. It allows a local user with access to the Windows host to bind to Splunk's management port before the Splunk service starts, then intercept authentication tokens from child processes as they start up.

The root cause is that the Windows management-port listener does not apply exclusive address-binding protections before the service starts, leaving a window in which another local process can claim the port. An attacker who captures these tokens can use them to compromise the integrity and confidentiality of all data and services managed by that Splunk instance.

Reference

  1. https://advisory.splunk.com/advisories/SVD-2026-0801
  2. https://www.cve.org/CVERecord?id=CVE-2026-76259