Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to add attacker-controlled content to system-level messages on the Splunk platform instance. The vulnerability is possible because the collect command does not validate the index name before processing the value. For more information see collect (https://help.splunk.com/en/splunk-enterprise/search/spl-search-reference/10.4/search-commands/collect), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and System endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/rest-api-reference/10.4/system-endpoints/system-endpoint-descriptions) in the Splunk documentation.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Injection of Attacker-Controlled Content into System Messages
Action: Patch
AI Analysis

Impact

The vulnerability arises from an improper validation of the index name in the collect SPL command. An attacker who controls an SPL query via a role possessing the run_collect capability can inject arbitrary content into system‑level messages. This results in unauthorized modification of Splunk internal logs and messages. The weakness is a classic input validation flaw (CWE‑20).

Affected Systems

Affected systems are Splunk Enterprise installations where the collect command is available and the user’s role includes run_collect. Versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are vulnerable, regardless of the instance size or deployment type. Administrators should confirm whether any users or roles have run_collect, which is often granted to administrators or security analysts.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate overall risk. The vulnerability requires legitimate access to Splunk and a role with run_collect, so its exploitation vector is limited to internal or compromised accounts. EPSS is unavailable, and the issue is not listed in KEV, suggesting lower attack prevalence. Nevertheless, attackers could leverage this to tamper with system messages, potentially hiding malicious activity or confusing audit trails. Immediate remediation by patching is recommended to eliminate the risk.

Generated by OpenCVE AI on October 7, 2026 at 22:58 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, or 9.4.15 or later.
  • Remove or restrict the run_collect capability from non‑trusted roles or users.
  • Monitor system‑level messages for unauthorized changes and review logs for injected content.

Generated by OpenCVE AI on October 7, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to add attacker-controlled content to system-level messages on the Splunk platform instance. The vulnerability is possible because the collect command does not validate the index name before processing the value. For more information see collect (https://help.splunk.com/en/splunk-enterprise/search/spl-search-reference/10.4/search-commands/collect), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and System endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/rest-api-reference/10.4/system-endpoints/system-endpoint-descriptions) in the Splunk documentation.
Title Improper Input Validation through the collect Command in Splunk Enterprise
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-08T13:35:47.065Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76273

cve-icon Vulnrichment

Updated: 2026-10-08T13:35:36.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T21:17:18.337

Modified: 2026-10-08T20:08:45.857

Link: CVE-2026-76273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-20

    Improper Input Validation