Input validation error in Splunk Enterprise - CVE-2026-76323

 

Input validation error in Splunk Enterprise - CVE-2026-76323

Published: August 20, 2026


Vulnerability identifier: #VU144456
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76323
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass SPL risky command safeguards.

The vulnerability exists due to improper input validation in the Job Details dashboard when placing a caller-supplied search identifier into SPL searches. A remote user can trick another user into opening a crafted dashboard link to run injected SPL with that user's permissions.

The initiating user should not be able to exploit the vulnerability at will.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76323

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins