Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and availability. The vulnerability is possible because scheduled search alert action configuration does not properly restrict user-specific alert action settings before the search scheduler runs alert actions. For more information see Create scheduled alerts (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/create-alerts/create-scheduled-alerts), Set up alert actions (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/configure-alert-actions/set-up-alert-actions), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Configuration file precedence (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/administer-splunk-enterprise-with-configuration-files/configuration-file-precedence) in the Splunk documentation.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Splunk Enterprise versions below the specified patches, a user who holds the schedule_search capability can trigger scheduled search alerts that execute arbitrary Search Processing Language commands with system-level privilege. This flaw enables the attacker to read all credentials stored in the credential store and potentially modify critical data, compromising system integrity and availability. The vulnerability stems from unsanitized handling of user‑specific alert action settings before the search scheduler runs the alert actions, reflecting an access control weakness described by CWE‑269.

Affected Systems

Splunk Enterprise users running any pre‑10.4.2 release (specifically versions 10.4.1 and earlier, 10.2.5 and earlier, 10.0.8 and earlier, and 9.4.13 and earlier) are affected. The remedial versions are 10.4.2, 10.2.6, 10.0.9, and 9.4.14 or later for each respective release line.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. No EPSS data is available, and the issue is not currently listed in the CISA KEV catalog. The attack vector is likely local or via privileged users who have the schedule_search capability; an attacker could configure or modify a scheduled search to execute arbitrary SPL, leading to privilege escalation within the Splunk environment.

Generated by OpenCVE AI on August 20, 2026 at 10:20 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Remove the rest_properties_set or schedule_search capability from custom roles that do not need to write user-specific configurations or create and dispatch scheduled searches. For more information see [Define roles on the Splunk platform with capabilities](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2 or later, 10.2.6 or later, 10.0.9 or later, or 9.4.14 or later, depending on the release line.
  • Remove the rest_properties_set or schedule_search capabilities from any custom roles that do not need to write user‑specific configurations or create and dispatch scheduled searches.
  • Audit and restrict scheduled search alert configurations, ensuring only trusted users with proper authorization can trigger alert actions.

Generated by OpenCVE AI on August 20, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and availability. The vulnerability is possible because scheduled search alert action configuration does not properly restrict user-specific alert action settings before the search scheduler runs alert actions. For more information see Create scheduled alerts (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/create-alerts/create-scheduled-alerts), Set up alert actions (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/configure-alert-actions/set-up-alert-actions), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Configuration file precedence (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/administer-splunk-enterprise-with-configuration-files/configuration-file-precedence) in the Splunk documentation.
Title Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterprise
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:54.855Z

Reserved: 2026-08-19T12:02:03.618Z

Link: CVE-2026-76253

cve-icon Vulnrichment

Updated: 2026-08-27T16:16:32.551Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:13.130

Modified: 2026-08-27T17:20:01.690

Link: CVE-2026-76253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:30:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management