Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76320
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SPL searches.
The vulnerability exists due to SPL injection through cross-site request forgery in the Event Type Builder when retaining SPL-affecting request values. A remote attacker can trick a user into initiating a crafted browser request to run arbitrary SPL searches on their behalf.
The unauthenticated user should not be able to exploit the vulnerability at will.