Missing Authorization in Splunk Enterprise - CVE-2026-76255

 

Missing Authorization in Splunk Enterprise - CVE-2026-76255

Published: August 20, 2026


Vulnerability identifier: #VU144433
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76255
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SPL commands.

The vulnerability exists due to missing authorization in Splunk Web Data Model Editor when running base searches for auto-extracted fields. A remote user can trick another user into initiating a crafted browser request to run arbitrary SPL commands with that user's permissions.

The initiating user should not be able to exploit the vulnerability at will.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76255

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins