{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-76259/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-76259"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Splunk Enterprise for Windows"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","splunk","windows","cve-2026-76259"],"_cs_type":"advisory","_cs_vendors":["Splunk"],"content_html":"\u003cp\u003eSplunk Enterprise for Windows (versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14) is susceptible to a local privilege escalation vulnerability tracked as CVE-2026-76259. The issue stems from the Windows management-port listener failing to enforce exclusive address binding protections prior to the service initialization. A local user with existing access to the Windows host can exploit this by binding to the management port before the Splunk service starts. By doing so, the attacker can intercept authentication tokens generated by subsequent child processes. This unauthorized token access potentially allows an attacker to compromise the integrity and confidentiality of all data available to the service account running Splunk Enterprise. This flaw is particularly impactful for environments where the service account operates with high privileges, as successful exploitation results in full service-level compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-76259 allows a local attacker to escalate privileges to the level of the service account running Splunk Enterprise. This enables unauthorized access to indexed data, system configuration, and internal Splunk management functions, potentially leading to full control over the Splunk deployment on the affected Windows host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Splunk Enterprise for Windows instances to the patched versions: 10.4.2, 10.2.6, 10.0.9, 9.4.13, or 9.3.14.\u003c/li\u003e\n\u003cli\u003eAudit Windows host local user permissions to ensure that only authorized accounts can initiate services or manage networking configurations on Splunk servers.\u003c/li\u003e\n\u003cli\u003eReview service account permissions to ensure the principle of least privilege is applied, limiting the potential impact if a service account token is compromised.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T22:40:48Z","date_published":"2026-08-19T22:40:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-splunk-cve-2026-76259/","summary":"A local privilege escalation vulnerability in Splunk Enterprise for Windows allows attackers to bind to the management port before service startup, enabling the interception of authentication tokens.","title":"Privilege Escalation in Splunk Enterprise for Windows via Port Binding","url":"https://feed.craftedsignal.io/briefs/2026-08-splunk-cve-2026-76259/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-76259","version":"https://jsonfeed.org/version/1.1"}