Command injection in Splunk Enterprise - CVE-2026-76339

 

Command injection in Splunk Enterprise - CVE-2026-76339

Published: August 20, 2026


Vulnerability identifier: #VU144471
CSH Severity: Low
CVSS v4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76339
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SPL commands.

The vulnerability exists due to command injection in the geostats command when validating input before processing searches. A remote user can trick another user into initiating an attacker-controlled geostats search to run injected SPL with that user's permissions.

The initiating user should not be able to exploit the vulnerability at will.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76339

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins