Incorrect authorization in Splunk Enterprise - CVE-2026-76342

 

Incorrect authorization in Splunk Enterprise - CVE-2026-76342

Published: August 20, 2026


Vulnerability identifier: #VU144474
CSH Severity: Low
CVSS v4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76342
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass SPL risky command safeguards.

The vulnerability exists due to improper authorization in the Table Editor field-summary search when preparing the Initial Data step. A remote user can store risky SPL commands in a shared Table Editor dataset and trick another user into opening it to run the commands with that user's permissions.

Exploitation requires the power Splunk role.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76342

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins