Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76327

 

Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76327

Published: August 20, 2026


Vulnerability identifier: #VU144460
CSH Severity: Medium
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76327
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SPL commands.

The vulnerability exists due to SPL injection in Splunk Secure Gateway dashboards when using caller-supplied values in dashboard searches. A remote attacker can trick a privileged user into opening a crafted Splunk Web URL to run arbitrary SPL commands with that user's permissions.

The unauthenticated user should not be able to exploit the vulnerability at will.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76327

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins