Skip to content
Threat Feed
high advisory

Privilege Escalation in Splunk Enterprise for Windows via Port Binding

A local privilege escalation vulnerability in Splunk Enterprise for Windows allows attackers to bind to the management port before service startup, enabling the interception of authentication tokens.

CVE search metadata

CVE search record: CVE-2026-76259. Severity: high. CVSS: 8.8. KEV: no. Product: Splunk Enterprise for Windows. Brief: Privilege Escalation in Splunk Enterprise for Windows via Port Binding. Brief link: https://feed.craftedsignal.io/briefs/2026-08-splunk-cve-2026-76259/

Splunk Enterprise for Windows (versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14) is susceptible to a local privilege escalation vulnerability tracked as CVE-2026-76259. The issue stems from the Windows management-port listener failing to enforce exclusive address binding protections prior to the service initialization. A local user with existing access to the Windows host can exploit this by binding to the management port before the Splunk service starts. By doing so, the attacker can intercept authentication tokens generated by subsequent child processes. This unauthorized token access potentially allows an attacker to compromise the integrity and confidentiality of all data available to the service account running Splunk Enterprise. This flaw is particularly impactful for environments where the service account operates with high privileges, as successful exploitation results in full service-level compromise.

Impact

Successful exploitation of CVE-2026-76259 allows a local attacker to escalate privileges to the level of the service account running Splunk Enterprise. This enables unauthorized access to indexed data, system configuration, and internal Splunk management functions, potentially leading to full control over the Splunk deployment on the affected Windows host.

Recommendation

  • Upgrade all Splunk Enterprise for Windows instances to the patched versions: 10.4.2, 10.2.6, 10.0.9, 9.4.13, or 9.3.14.
  • Audit Windows host local user permissions to ensure that only authorized accounts can initiate services or manage networking configurations on Splunk servers.
  • Review service account permissions to ensure the principle of least privilege is applied, limiting the potential impact if a service account token is compromised.

Immediate actions

Patch Splunk Enterprise for Windows to versions 10.4.2, 10.2.6, 10.0.9, 9.4.13, or 9.3.14

IT Operations 72h

Mitigations

Review and restrict local user access to Splunk Enterprise host servers

immediate IT Operations

CVE-2026-76259