Command injection in Splunk Enterprise - CVE-2026-76328
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to command injection in Splunk Web when processing dashboard PDF exports. A remote user can store attacker-controlled SPL in a dashboard and trick another user into exporting it as a PDF to run the SPL with that user's permissions.
Exploitation requires the power Splunk role.