Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76316

 

Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76316

Published: August 20, 2026


Vulnerability identifier: #VU144449
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76316
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SPL commands.

The vulnerability exists due to SPL injection in Deployment Server broker registration when placing client identifiers into dispatched searches. A remote attacker can register a crafted Deployment Server client identity to store an SPL pipeline that runs when an administrator opens the affected workflow.

Successful exploitation requires an administrator to open the Add Data forwarder workflow.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76316

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins