Input validation error in Splunk Enterprise - CVE-2026-76332
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to improper input validation in Analytics Workspace when building searches. A remote attacker can trick a user into opening a crafted Analytics Workspace link to run attacker-controlled SPL with that user's permissions.
The unauthenticated user should not be able to exploit the vulnerability at will.