Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect system integrity and availability. The vulnerability is possible because Splunk Web evaluates manager Extensible Markup Language expressions without sufficient input restrictions, and the associated configuration route does not require the capability expected for manager configuration changes. For more information see About configuration files (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.4/administer-splunk-enterprise-with-configuration-files/about-configuration-files) in the Splunk documentation.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows non‑admin users to submit crafted Splunk Web Manager Configuration (manager Extensible Markup Language) data that is processed without adequate input validation, a form of code injection (CWE‑94). Executing this payload gives the attacker full data access and the ability to alter the system’s integrity and availability.

Affected Systems

The vulnerability affects Splunk Enterprise installations running any of the following patched releases or earlier: versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Only the mentioned product and vendor are impacted; no other third‑party or partner software is listed.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score is not available. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves a legitimate user with a non‑admin role accessing the web interface to submit malicious configuration content; because the appropriate capability check is missing, an attacker can achieve code execution without elevated privileges. Given the high impact and the lack of built‑in mitigation, the risk is considered significant and a timelier response is advisable.

Generated by OpenCVE AI on August 20, 2026 at 10:53 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

The vulnerability affects instances with Splunk Web turned on. Turning Splunk Web off is a possible workaround. See [Disable unnecessary Splunk Enterprise components](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/install-splunk-enterprise-securely/disable-unnecessary-splunk-enterprise-components) and the [web.conf](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/web.conf) configuration specification file for more information on turning off Splunk Web.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to a fixed release—10.4.2, 10.2.6, 10.0.9, or 9.4.14, or any newer version.
  • Disable the Splunk Web component on affected hosts as a temporary workaround, following the vendor’s disabling instructions.
  • Restrict web access to only users with admin or power roles and review role assignments to ensure no unnecessary roles can reach the web interface.
  • Audit and sanitize manager configuration files to ensure no unintended extensions remain active.

Generated by OpenCVE AI on August 20, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect system integrity and availability. The vulnerability is possible because Splunk Web evaluates manager Extensible Markup Language expressions without sufficient input restrictions, and the associated configuration route does not require the capability expected for manager configuration changes. For more information see About configuration files (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.4/administer-splunk-enterprise-with-configuration-files/about-configuration-files) in the Splunk documentation.
Title Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:56.442Z

Reserved: 2026-08-19T12:02:03.625Z

Link: CVE-2026-76314

cve-icon Vulnrichment

Updated: 2026-08-27T16:16:57.823Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:15.250

Modified: 2026-08-27T17:20:08.737

Link: CVE-2026-76314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')