Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76254
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to improper neutralization and missing command safeguards in Dataset Explorer when building SPL searches. A remote attacker can trick a user into opening a crafted link to dispatch arbitrary SPL pipelines with that user's privileges.
The unauthenticated user should not be able to exploit the vulnerability at will.