Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76327
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to SPL injection in Splunk Secure Gateway dashboards when using caller-supplied values in dashboard searches. A remote attacker can trick a privileged user into opening a crafted Splunk Web URL to run arbitrary SPL commands with that user's permissions.
The unauthenticated user should not be able to exploit the vulnerability at will.