Command injection in Splunk Enterprise - CVE-2026-76339
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to command injection in the geostats command when validating input before processing searches. A remote user can trick another user into initiating an attacker-controlled geostats search to run injected SPL with that user's permissions.
The initiating user should not be able to exploit the vulnerability at will.