Incorrect authorization in Splunk Enterprise - CVE-2026-76341
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to bypass SPL risky command safeguards.
The vulnerability exists due to improper authorization in Table Editor dataset initial data handling when preparing initial data. A remote user can store attacker-controlled SPL in a shared Table Editor dataset and trick another user into opening it to run the SPL with that user's permissions.
Exploitation requires the power Splunk role.