Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76349

 

Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76349

Published: August 20, 2026


Vulnerability identifier: #VU144481
CSH Severity: Low
CVSS v4: 5.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76349
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SPL commands.

The vulnerability exists due to SPL injection in Splunk Web form tokens when substituting URL-supplied token values into SPL searches. A remote attacker can trick a user into opening a crafted Splunk Web link to run arbitrary SPL commands with that user's permissions.

The unauthenticated user should not be able to exploit the vulnerability at will.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76349

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins