Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76254

 

Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76254

Published: August 20, 2026


Vulnerability identifier: #VU144432
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76254
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SPL commands.

The vulnerability exists due to improper neutralization and missing command safeguards in Dataset Explorer when building SPL searches. A remote attacker can trick a user into opening a crafted link to dispatch arbitrary SPL pipelines with that user's privileges.

The unauthenticated user should not be able to exploit the vulnerability at will.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76254

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins