Improper privilege management in Splunk Enterprise - CVE-2026-76350
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in PDF attachments for email alert actions when the search scheduler renders PDF attachments. A remote user can configure PDF attachments in the email alert action workflow to run arbitrary SPL commands with system-level privileges.
Exploitation requires a role with the schedule_search capability.