Description
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a dashboard. When another authenticated user exports the dashboard as a Portable Document Format (PDF) file, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user. The vulnerability is possible because Splunk Web does not sufficiently validate dashboard content before processing PDF exports. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see Generate PDFs of your reports and dashboards (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.4/report-management/generate-pdfs-of-your-reports-and-dashboards) in the Splunk documentation.
Published: 2026-08-19
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Splunk Enterprise versions earlier than 10.4.1, 10.2.6, 10.0.9, and 9.4.14 allow a user with the "power" role to embed attacker‑controlled SPL in a dashboard. When another authenticated user exports that dashboard to PDF, the system runs the injected SPL using the exporting user's permissions. The result is that an attacker can read or alter any data the exporting user is authorized to see, effectively bypassing normal access control boundaries. This flaw is a typical command injection vulnerability (CWE‑77) that does not directly affect the host OS but can compromise the integrity and confidentiality of Splunk data.

Affected Systems

The affected product is Splunk Enterprise. All releases prior to 10.4.1, 10.2.6, 10.0.9, and 9.4.14 are vulnerable. Upgrading to at least 10.4.2, 10.2.6, 10.0.9, or 9.4.14 (and later) removes the flaw.

Risk and Exploitability

The CVSS score of 6.7 indicates a moderate to high risk. Exploitation requires a legitimate authenticated session and a phishing‑style trick to have the target user initiate a PDF export. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploits at present. Nevertheless, the potential for data exfiltration or tampering warrants prompt attention.

Generated by OpenCVE AI on August 20, 2026 at 09:53 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

The vulnerability affects instances with Splunk Web turned on. Turning Splunk Web off is a possible workaround. See [Disable unnecessary Splunk Enterprise components](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/install-splunk-enterprise-securely/disable-unnecessary-splunk-enterprise-components) and the [web.conf](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/web.conf) configuration specification file for more information on turning off Splunk Web.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, 9.4.14 or later depending on your environment.
  • Disable the Splunk Web component if an immediate patch cannot be applied, thereby removing the PDF export vector that triggers the injection.
  • Limit assignment of the "power" role to trusted administrators and audit existing dashboards for embedded SPL to prevent malicious payloads.

Generated by OpenCVE AI on August 20, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a dashboard. When another authenticated user exports the dashboard as a Portable Document Format (PDF) file, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user. The vulnerability is possible because Splunk Web does not sufficiently validate dashboard content before processing PDF exports. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see Generate PDFs of your reports and dashboards (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.4/report-management/generate-pdfs-of-your-reports-and-dashboards) in the Splunk documentation.
Title SPL Injection through Splunk Web in Splunk Enterprise
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:57.720Z

Reserved: 2026-08-19T12:02:03.626Z

Link: CVE-2026-76328

cve-icon Vulnrichment

Updated: 2026-08-27T16:17:22.363Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:17.033

Modified: 2026-08-27T17:20:13.030

Link: CVE-2026-76328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')