Missing Authorization in Splunk Enterprise - CVE-2026-76255
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to missing authorization in Splunk Web Data Model Editor when running base searches for auto-extracted fields. A remote user can trick another user into initiating a crafted browser request to run arbitrary SPL commands with that user's permissions.
The initiating user should not be able to exploit the vulnerability at will.