Code Injection in Splunk Enterprise - CVE-2026-76335
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to code injection in Splunk Web Manager XML configuration when accepting manager XML configuration changes. A remote user can write a malicious manager XML configuration to execute operating-system commands as the Splunk Enterprise service account.