Description
In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (REST) API, including private SPL2 module definitions belonging to other users. The vulnerability is possible because Splunk Enterprise and Splunk Cloud Platform do not parameterize user-supplied values before using them in database queries for SPL2 module filtering. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.

Splunk Enterprise versions 10.2.x, 10.0.x, and 9.4.x are not affected.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access via SQL injection
Action: Patch Upgrade
AI Analysis

Impact

In Splunk Enterprise versions prior to 10.4.3, a user holding the list_spl2_modules capability can inject SQL into the SPL2 module filtering process. This injection is possible because the system does not parameterize user‑supplied values before using them in database queries. The result is that an attacker can query the underlying data store through the REST API and read all relevant data, including private SPL2 module definitions that belong to other users, leading to a confidentiality breach. The underlying weakness aligns with CWE‑89, an unsanitized SQL query condition.

Affected Systems

Splunk, Splunk Enterprise is affected. Any release below 10.4.3, except those specifically noted as not affected (10.2.x, 10.0.x, and 9.4.x), is vulnerable. This means that versions such as 10.3.x and earlier 9.x releases fall into this risk window.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available, so the exact exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation as of now. The likely attack vector requires an authenticated user with the list_spl2_modules capability, which can be exercised via the SPL2 module filtering interface or REST API calls. While the risk is moderate, it offers direct read access to sensitive configuration data, warranting timely remediation.

Generated by OpenCVE AI on October 7, 2026 at 22:59 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, or 9.4.15, or newer.
  • If an immediate upgrade is not possible, remove or restrict the list_spl2_modules capability from users or roles that do not require it.
  • Limit access to the REST API that exposes SPL2 module data and enable detailed logging to detect suspicious query activity.

Generated by OpenCVE AI on October 7, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (REST) API, including private SPL2 module definitions belonging to other users. The vulnerability is possible because Splunk Enterprise and Splunk Cloud Platform do not parameterize user-supplied values before using them in database queries for SPL2 module filtering. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation. Splunk Enterprise versions 10.2.x, 10.0.x, and 9.4.x are not affected.
Title Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splunk Enterprise
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:32.327Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76270

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:17.907

Modified: 2026-10-07T21:17:17.907

Link: CVE-2026-76270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')