SB2026082083 - Multiple vulnerabilities in Splunk Enterprise
Published: August 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 60 vulnerabilities.
1) Missing Authorization (CVE-ID: CVE-2026-76322)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to missing authorization in Dashboard Studio when dashboard search query options reach search dispatch. A remote user can craft a dashboard and trick another user into initiating a browser request to run attacker-controlled SPL.
The initiating user should not be able to exploit the vulnerability at will.
2) Information disclosure (CVE-ID: CVE-2026-76262)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication in the Prometheus metrics endpoint of the Edge Processor SPL2 Preview sidecar when exposing service metrics. A remote attacker can send requests to the metrics endpoint to retrieve runtime and build metadata.
3) Improper Authorization (CVE-ID: CVE-2026-76352)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper authorization in generic transforms configuration endpoints when creating or modifying scripted lookup definitions through the REST API. A remote user can create or modify a scripted lookup to execute arbitrary code.
The issue involves installed lookup scripts running with the permissions of the user account running Splunk Enterprise.
4) Missing Authorization (CVE-ID: CVE-2026-76251)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and make limited content changes.
The vulnerability exists due to missing authorization in the Splunk App for Splunk Observability Cloud REST API endpoint handlers when forwarding requests to Splunk Observability Cloud. A remote user can send crafted REST API requests to disclose data available to the stored access token and make limited content changes.
The request can include the Splunk Observability Cloud access token stored for the app.
5) Cross-site scripting (CVE-ID: CVE-2026-76252)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in Splunk Web message validation when handling page messages. A remote attacker can trick a user into visiting a malicious web page to execute unauthorized JavaScript in that user's browser.
The unauthenticated user should not be able to exploit the vulnerability at will.
6) Improper privilege management (CVE-ID: CVE-2026-76253)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in scheduled search alert action configuration when running alert actions. A remote user can configure user-specific alert action settings to run arbitrary SPL commands with the highest level of system privilege.
Exploitation requires a role with the schedule_search capability.
7) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-76254)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to improper neutralization and missing command safeguards in Dataset Explorer when building SPL searches. A remote attacker can trick a user into opening a crafted link to dispatch arbitrary SPL pipelines with that user's privileges.
The unauthenticated user should not be able to exploit the vulnerability at will.
8) Missing Authorization (CVE-ID: CVE-2026-76255)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to missing authorization in Splunk Web Data Model Editor when running base searches for auto-extracted fields. A remote user can trick another user into initiating a crafted browser request to run arbitrary SPL commands with that user's permissions.
The initiating user should not be able to exploit the vulnerability at will.
9) Information disclosure (CVE-ID: CVE-2026-76256)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to information exposure in Splunk Secure Gateway REST API endpoints when returning SAML setup and instance settings. A remote user can send REST API requests to disclose sensitive configuration information.
10) Missing Authorization (CVE-ID: CVE-2026-76257)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive secrets.
The vulnerability exists due to missing authorization in Splunk Secure Gateway REST API endpoints when processing deployment bundle, SAML setup, and companion app workflow requests. A remote user can send REST API requests to access Mobile Device Management signing secrets.
Exploitation requires permissions to list storage passwords without Splunk Secure Gateway administration privileges.
11) Use of Hard-coded Cryptographic Key (CVE-ID: CVE-2026-76258)
CWE-ID: CWE-321 - Use of Hard-coded Cryptographic Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose mobile user tokens.
The vulnerability exists due to use of a hard-coded cryptographic key in the Splunk Secure Gateway companion app registration handler when registering callback URLs. A remote user can register an arbitrary companion app to forward mobile user requests to an attacker-controlled URL.
12) Improper privilege management (CVE-ID: CVE-2026-76259)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper privilege management in the Windows management-port listener when the Splunk Enterprise service starts. A local user can bind to the management port before Splunk Enterprise starts to intercept authentication tokens from child processes.
Exploitation requires access to the Windows host.
13) Incorrect permission assignment for critical resource (CVE-ID: CVE-2026-76260)
CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose stored credentials.
The vulnerability exists due to incorrect permission assignment in the properties REST endpoint when reading stored credentials. A remote user can send REST API requests to read encrypted stored credentials.
Exploitation requires the rest_properties_get capability.
14) Incorrect permission assignment for critical resource (CVE-ID: CVE-2026-76261)
CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose private keys.
The vulnerability exists due to an insecure default access control list in the Splunk Secure Gateway App Key Value Store REST API when private-key migration remains incomplete. A remote user can send REST API requests to read Spacebridge asymmetric private keys.
Only upgraded instances with incomplete private-key migration are affected.
15) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-76263)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify data belonging to other users.
The vulnerability exists due to broken object level authorization in the data management orchestrator when deleting SPL2 modules. A remote user can send requests to delete SPL2 modules belonging to other users.
16) Input validation error (CVE-ID: CVE-2026-76323)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass SPL risky command safeguards.
The vulnerability exists due to improper input validation in the Job Details dashboard when placing a caller-supplied search identifier into SPL searches. A remote user can trick another user into opening a crafted dashboard link to run injected SPL with that user's permissions.
The initiating user should not be able to exploit the vulnerability at will.
17) SQL injection (CVE-ID: CVE-2026-76309)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute SQL queries.
The vulnerability exists due to SQL injection in the REST API when incorporating user-supplied filter values into database queries. A remote user can send crafted REST API requests to cause Splunk Enterprise to evaluate attacker-controlled text as part of a database query.
18) Improper access control (CVE-ID: CVE-2026-76310)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access data and affect system integrity.
The vulnerability exists due to improper access control in embedded report REST API requests when downloading dispatch archives. A remote attacker can use an embedded report token to download a search job dispatch archive and recover session material.
Exploitation requires possession of an embedded report token.
19) Improper access control (CVE-ID: CVE-2026-76311)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access data and affect system integrity.
The vulnerability exists due to improper access control in embedded report dispatch archives when processing archive download requests. A remote attacker can use an embedded report token to download a dispatch archive and use exposed session material.
Exploitation requires possession of an embedded report token.
20) Improper access control (CVE-ID: CVE-2026-76312)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access data and affect system integrity.
The vulnerability exists due to improper access control in embedded reports when enforcing the dispatch archive authorization boundary. A remote attacker can read the HTML source of a page that embeds a Splunk report to use exposed session material.
Exploitation requires access to the HTML source of a page that embeds a Splunk report.
21) Improper access control (CVE-ID: CVE-2026-76313)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the knowledge bundle upload REST API and distributed search bundle selection when handling caller-supplied knowledge bundles. A remote user can upload a malicious knowledge bundle and cause distributed search to use it to execute arbitrary code.
22) Code Injection (CVE-ID: CVE-2026-76314)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to code injection in Splunk Web Manager Configuration when evaluating manager XML expressions. A remote user can submit crafted manager configuration content to execute arbitrary code.
23) Code Injection (CVE-ID: CVE-2026-76315)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to code injection in Splunk Web Manager Configuration when evaluating manager configuration values. A remote user can submit manager configuration through the REST API path to execute arbitrary code.
24) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-76316)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to SPL injection in Deployment Server broker registration when placing client identifiers into dispatched searches. A remote attacker can register a crafted Deployment Server client identity to store an SPL pipeline that runs when an administrator opens the affected workflow.
Successful exploitation requires an administrator to open the Add Data forwarder workflow.
25) Path Traversal: \'/dir/../filename\' (CVE-ID: CVE-2026-76317)
CWE-ID: CWE-26 - Path Traversal: \'/dir/../filename\'
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read files and affect system integrity.
The vulnerability exists due to path traversal in the lookup configuration REST API when checking lookup source paths. A remote user can send crafted lookup configuration requests to move readable files into a lookup the user controls.
26) Cross-site scripting (CVE-ID: CVE-2026-76318)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in Splunk Web alert trigger condition markup when rendering alert threshold values. A remote user can store a malicious script in an alert trigger condition field and trick another user into opening a crafted link to execute it.
Exploitation requires the schedule_search capability.
27) Missing Authorization (CVE-ID: CVE-2026-76319)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to missing authorization in Federated Search dispatch flow when accepting caller-controlled bundle selection. A remote user can send crafted federated search requests to cause remote code execution.
28) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-76320)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SPL searches.
The vulnerability exists due to SPL injection through cross-site request forgery in the Event Type Builder when retaining SPL-affecting request values. A remote attacker can trick a user into initiating a crafted browser request to run arbitrary SPL searches on their behalf.
The unauthenticated user should not be able to exploit the vulnerability at will.
29) Command injection (CVE-ID: CVE-2026-76321)
CWE-ID: CWE-77 - Command injection
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute unauthorized searches.
The vulnerability exists due to command injection in Splunk Web nearby-event searches when building SPL from caller-supplied values. A remote attacker can send crafted nearby-event search requests to inject arbitrary SPL.
30) Missing Authentication for Critical Function (CVE-ID: CVE-2026-76355)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication in the Edge Processor service endpoint when retrieving pipeline configurations. A remote attacker can send REST API requests to retrieve information contained in Edge Processor pipeline configurations.
Edge Processor must be turned on.
31) Cross-site scripting (CVE-ID: CVE-2026-76324)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in Splunk Web Tours when rendering tour content and navigation links. A remote user can create a malicious tour and trick another user into opening a crafted tour link to execute JavaScript.
Exploitation requires the power Splunk role.
32) Command injection (CVE-ID: CVE-2026-76339)
CWE-ID: CWE-77 - Command injection
CVSSv4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to command injection in the geostats command when validating input before processing searches. A remote user can trick another user into initiating an attacker-controlled geostats search to run injected SPL with that user's permissions.
The initiating user should not be able to exploit the vulnerability at will.
33) Cross-site scripting (CVE-ID: CVE-2026-76326)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in the dashboard table renderer when handling sparkline tooltip options. A remote user can store a dashboard view that executes JavaScript when another user opens it and hovers over a sparkline table cell.
34) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-76327)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to SPL injection in Splunk Secure Gateway dashboards when using caller-supplied values in dashboard searches. A remote attacker can trick a privileged user into opening a crafted Splunk Web URL to run arbitrary SPL commands with that user's permissions.
The unauthenticated user should not be able to exploit the vulnerability at will.
35) Command injection (CVE-ID: CVE-2026-76328)
CWE-ID: CWE-77 - Command injection
CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to command injection in Splunk Web when processing dashboard PDF exports. A remote user can store attacker-controlled SPL in a dashboard and trick another user into exporting it as a PDF to run the SPL with that user's permissions.
Exploitation requires the power Splunk role.
36) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-76329)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to SPL injection in Monitoring Console dashboard inputs when building dashboard searches. A remote attacker can trick a user into opening a crafted Monitoring Console link to run attacker-controlled SPL with that user's permissions.
The unauthenticated user should not be able to exploit the vulnerability at will.
37) Input validation error (CVE-ID: CVE-2026-76330)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to improper input validation in Monitoring Console forwarder filters when building forwarder dashboard searches. A remote attacker can trick a user into opening a crafted Monitoring Console link to run attacker-controlled SPL with that user's permissions.
The unauthenticated user should not be able to exploit the vulnerability at will.
38) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-76331)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to SPL injection in saved-search dispatch requests when validating caller-supplied time values. A remote user can send crafted REST API requests to inject SPL into saved-search dispatch.
39) Input validation error (CVE-ID: CVE-2026-76332)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to improper input validation in Analytics Workspace when building searches. A remote attacker can trick a user into opening a crafted Analytics Workspace link to run attacker-controlled SPL with that user's permissions.
The unauthenticated user should not be able to exploit the vulnerability at will.
40) Cross-site scripting (CVE-ID: CVE-2026-76333)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in Dashboard Studio workflow actions when validating workflow-action URLs. A remote user can store a crafted workflow action and trick another user into selecting it to execute JavaScript.
Exploitation requires the power Splunk role.
41) Cross-site request forgery (CVE-ID: CVE-2026-76334)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to cross-site request forgery in Dashboard Studio workflow actions when submitting workflow-action URLs. A remote user can store a workflow action containing attacker-controlled SPL and trick another user into selecting it to run the SPL with that user's permissions.
Exploitation requires the power Splunk role.
42) Code Injection (CVE-ID: CVE-2026-76335)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to code injection in Splunk Web Manager XML configuration when accepting manager XML configuration changes. A remote user can write a malicious manager XML configuration to execute operating-system commands as the Splunk Enterprise service account.
43) Missing Authorization (CVE-ID: CVE-2026-76336)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to delete SPL2 modules.
The vulnerability exists due to missing authorization in the SPL2 module management REST API when processing module deletion requests. A remote user can send REST API requests to delete SPL2 modules across apps and users.
44) Path traversal (CVE-ID: CVE-2026-76337)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read files outside the static directory.
The vulnerability exists due to path traversal in Splunk Web static file serving when handling static file requests. A remote attacker can send crafted static file requests to read JavaScript files outside the Splunk Web static directory.
45) Missing Authorization (CVE-ID: CVE-2026-76340)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to affect system integrity.
The vulnerability exists due to missing authorization in the REST API token-key reload action when reloading token-signing keys. A remote attacker can send REST API requests to cause Splunk Enterprise to reload token-signing keys.
46) Cross-site scripting (CVE-ID: CVE-2026-76325)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in Splunk Web auto-tour handling when resolving ui-tour knowledge objects from the app namespace. A remote user can store and share a malicious ui-tour knowledge object to execute JavaScript when another user visits a standard Splunk Web page.
Exploitation requires the power Splunk role.
47) Incorrect authorization (CVE-ID: CVE-2026-76341)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass SPL risky command safeguards.
The vulnerability exists due to improper authorization in Table Editor dataset initial data handling when preparing initial data. A remote user can store attacker-controlled SPL in a shared Table Editor dataset and trick another user into opening it to run the SPL with that user's permissions.
Exploitation requires the power Splunk role.
48) Incorrect authorization (CVE-ID: CVE-2026-76342)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass SPL risky command safeguards.
The vulnerability exists due to improper authorization in the Table Editor field-summary search when preparing the Initial Data step. A remote user can store risky SPL commands in a shared Table Editor dataset and trick another user into opening it to run the commands with that user's permissions.
Exploitation requires the power Splunk role.
49) SQL injection (CVE-ID: CVE-2026-76343)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute SQL queries.
The vulnerability exists due to SQL injection in the Data Orchestration jobs endpoint when building database queries from user-controlled job filter values. A remote user can send crafted REST API requests to execute attacker-chosen SQL queries.
50) Path Traversal: \'dir/../../filename\' (CVE-ID: CVE-2026-76344)
CWE-ID: CWE-27 - Path Traversal: \'dir/../../filename\'
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to write files to arbitrary locations.
The vulnerability exists due to path traversal in the Search Dispatch REST API when using a search identifier to create a dispatch directory. A remote user can supply a crafted search identifier to write dispatch metadata to an arbitrary location on the host.
51) Improper access control (CVE-ID: CVE-2026-76345)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the search head cluster member bundle REST API when validating bundle paths and accepting bundle content. A remote privileged user can use the REST API to write files to writable locations and execute arbitrary code.
52) Cross-site scripting (CVE-ID: CVE-2026-76346)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in Splunk Web dashboard sparkline format options when rendering tooltip values. A remote user can store a malicious script in dashboard sparkline format options and trick another user into viewing the dashboard.
Exploitation requires the power Splunk role.
53) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-76347)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to send system-authenticated requests to internal services.
The vulnerability exists due to server-side request forgery in Splunk Secure Gateway report notifications when validating report notification path values. A remote user can send crafted report notification requests to cause system-authenticated requests to internal Splunk services.
54) Missing Authorization (CVE-ID: CVE-2026-76348)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to missing authorization in Search Head Cluster member control endpoints when applying read-only authorization to state-changing actions. A remote privileged user can send a read request to member control endpoints to change cluster state.
55) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-76349)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to SPL injection in Splunk Web form tokens when substituting URL-supplied token values into SPL searches. A remote attacker can trick a user into opening a crafted Splunk Web link to run arbitrary SPL commands with that user's permissions.
The unauthenticated user should not be able to exploit the vulnerability at will.
56) Improper privilege management (CVE-ID: CVE-2026-76350)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in PDF attachments for email alert actions when the search scheduler renders PDF attachments. A remote user can configure PDF attachments in the email alert action workflow to run arbitrary SPL commands with system-level privileges.
Exploitation requires a role with the schedule_search capability.
57) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-76351)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to send system-authenticated REST API requests.
The vulnerability exists due to server-side request forgery in Splunk Secure Gateway report notifications when constructing Splunk Enterprise REST API requests from decoded report notification identifiers. A remote user can send crafted report notification data to modify Splunk platform configuration.
58) Path Traversal: \'../filedir\' (CVE-ID: CVE-2026-76353)
CWE-ID: CWE-24 - Path Traversal: \'../filedir\'
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to delete arbitrary files.
The vulnerability exists due to path traversal in knowledge bundle delta processing when restricting removal paths to the staging directory. A remote user can submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager.
59) Improper Neutralization of Null Byte or NUL Character (CVE-ID: CVE-2026-76354)
CWE-ID: CWE-158 - Improper Neutralization of Null Byte or NUL Character
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to delete or overwrite files.
The vulnerability exists due to improper neutralization of NUL bytes in Search Head Clustering bundle replication when constructing member bundle paths. A remote user can send crafted REST API requests to delete or temporarily overwrite files writable by Splunk Enterprise processes.
The target described is a non-captain search head cluster member.
60) Improper Authentication (CVE-ID: CVE-2026-76338)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to forge an administrative session token.
The vulnerability exists due to improper authentication in distributed search authentication token endpoint when processing distributed search token requests. A remote attacker can send a crafted token request to forge an administrative session token.
Exploitation requires access to a trusted distributed search private key.
Remediation
Install update from vendor's website.