Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role into opening a crafted link to Monitoring Console. When that user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could expose data available to that user or modify lookup data. The vulnerability is possible because Monitoring Console does not sufficiently validate data used to build dashboard searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will.
Published: 2026-08-19
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Monitoring Console in Splunk Enterprise does not validate data used to build dashboard searches, allowing an unauthenticated attacker to craft a link that, when opened by a user with the admin role, runs attacker‑controlled Search Processing Language (SPL) using that user's permissions. The injected SPL may expose data the user can access or modify lookup data, effectively granting the attacker escalation of privileges and potential data tampering or disclosure.

Affected Systems

Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected. The vulnerability applies to instances with Splunk Web enabled, as the crafted link is delivered through a web interface.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, and the EPSS score is not available, making the exact exploitation probability unclear. The vulnerability is not listed in CISA's KEV catalog, suggesting it has not been widely observed in the wild. Exploitation requires social engineering; an unauthenticated attacker must trick an admin user into clicking the crafted link, which limits the attack surface but still presents a significant risk if successful.

Generated by OpenCVE AI on August 20, 2026 at 10:52 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

The vulnerability affects instances with Splunk Web turned on. Turning Splunk Web off is a possible workaround. See [Disable unnecessary Splunk Enterprise components](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/install-splunk-enterprise-securely/disable-unnecessary-splunk-enterprise-components) and the [web.conf](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/web.conf) configuration specification file for more information on turning off Splunk Web.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to a patched version (10.4.2, 10.2.6, 10.0.9, or 9.4.14 or newer).
  • If an immediate upgrade is not possible, disable Splunk Web to block the crafted link from being delivered through the web interface, following the guidance in Splunk documentation.
  • Restrict or remove the Monitoring Console feature from accounts that do not require it, ensuring only authorized administrators can access dashboard inputs.

Generated by OpenCVE AI on August 20, 2026 at 10:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role into opening a crafted link to Monitoring Console. When that user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could expose data available to that user or modify lookup data. The vulnerability is possible because Monitoring Console does not sufficiently validate data used to build dashboard searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will.
Title SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:22:13.844Z

Reserved: 2026-08-19T12:02:03.626Z

Link: CVE-2026-76329

cve-icon Vulnrichment

Updated: 2026-08-26T14:49:30.867Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:17.180

Modified: 2026-08-26T16:16:39.997

Link: CVE-2026-76329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic