Improper Neutralization of Special Elements in Data Query Logic in Splunk Enterprise - CVE-2026-76349
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SPL commands.
The vulnerability exists due to SPL injection in Splunk Web form tokens when substituting URL-supplied token values into SPL searches. A remote attacker can trick a user into opening a crafted Splunk Web link to run arbitrary SPL commands with that user's permissions.
The unauthenticated user should not be able to exploit the vulnerability at will.