Missing Authorization in Splunk Enterprise - CVE-2026-76322
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to missing authorization in Dashboard Studio when dashboard search query options reach search dispatch. A remote user can craft a dashboard and trick another user into initiating a browser request to run attacker-controlled SPL.
The initiating user should not be able to exploit the vulnerability at will.