Input validation error in Splunk Enterprise Security (ES) - CVE-2026-76387
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to access sensitive data and modify system integrity available to scheduled searches.
The vulnerability exists due to improper input validation in Analyst Queue search filter handling through the REST API when processing user-supplied filter field names in SPL searches. A remote user can inject crafted SPL through Analyst Queue search filters to access sensitive data and modify system integrity available to scheduled searches.
Exploitation requires a role that contains the mc_investigation_read capability.