Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76316
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to SPL injection in Deployment Server broker registration when placing client identifiers into dispatched searches. A remote attacker can register a crafted Deployment Server client identity to store an SPL pipeline that runs when an administrator opens the affected workflow.
Successful exploitation requires an administrator to open the Add Data forwarder workflow.