Incorrect authorization in Splunk Enterprise - CVE-2026-76342
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to bypass SPL risky command safeguards.
The vulnerability exists due to improper authorization in the Table Editor field-summary search when preparing the Initial Data step. A remote user can store risky SPL commands in a shared Table Editor dataset and trick another user into opening it to run the commands with that user's permissions.
Exploitation requires the power Splunk role.