Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a crafted Splunk Web Uniform Resource Locator (URL). The resulting dashboard searches could run arbitrary Search Processing Language (SPL) commands with the permissions available to the affected user. The commands could expose all relevant data available to that user and affect search results or lookup data. The vulnerability is possible because Splunk Secure Gateway dashboards do not correctly neutralize caller-supplied values before using them in dashboard searches. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will.
Published: 2026-08-19
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a SPL injection flaw that allows an unauthenticated attacker to craft a URL that, when opened by an admin-level user, causes the system to run arbitrary SPL commands with that user's privileges. This can expose sensitive data, alter search results, or modify lookup data, and is caused by the Secure Gateway app not properly neutralizing caller‑supplied values in dashboard searches.

Affected Systems

Splunk Enterprise versions older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 and Splunk Secure Gateway versions prior to 3.10.9, 3.9.23, or 3.8.70 are affected. In particular, users of Splunk Enterprise and its Secure Gateway app who have admin or sc_admin roles are vulnerable.

Risk and Exploitability

The CVSS base score of 6.4 indicates moderate severity. The EPSS score is not available, but the vulnerability still represents a potential risk because an attacker can coerce an admin to open a malicious URL. Although not listed in the CISA KEV catalog, an exploit would allow an attacker to execute arbitrary SPL commands, exposing or manipulating all data accessible to the targeted user. The vulnerability requires user interaction, making it less likely to be automated but still serious if phishing succeeds.

Generated by OpenCVE AI on August 20, 2026 at 10:18 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Upgrade Splunk Secure Gateway to versions 3.10.9, 3.9.23, and 3.8.70, or higher. If you can not upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later.
  • Upgrade Splunk Secure Gateway to version 3.10.9, 3.9.23, or 3.8.70 or later, or remove the Secure Gateway app if an upgrade is not possible.
  • If you do not use the Secure Gateway app or related functionality, disable or uninstall the app to eliminate the vulnerability.

Generated by OpenCVE AI on August 20, 2026 at 10:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
Vendors & Products Splunk splunk

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway
Vendors & Products Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a crafted Splunk Web Uniform Resource Locator (URL). The resulting dashboard searches could run arbitrary Search Processing Language (SPL) commands with the permissions available to the affected user. The commands could expose all relevant data available to that user and affect search results or lookup data. The vulnerability is possible because Splunk Secure Gateway dashboards do not correctly neutralize caller-supplied values before using them in dashboard searches. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will.
Title SPL Injection through Splunk Web in Splunk Secure Gateway
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L'}


Subscriptions

Splunk Splunk Splunk Enterprise Splunk Secure Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:22:21.208Z

Reserved: 2026-08-19T12:02:03.626Z

Link: CVE-2026-76327

cve-icon Vulnrichment

Updated: 2026-08-26T14:49:28.835Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:16.900

Modified: 2026-08-26T16:16:39.860

Link: CVE-2026-76327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:55Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic