Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Analytics Workspace. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions available to that user. The vulnerability is possible because Analytics Workspace does not sufficiently validate data used to build searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will.
Published: 2026-08-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Splunk Enterprise versions older than 10.4.2, 10.2.6, 10.0.9, and 9.4.14 allow an unauthenticated attacker to craft a link that an authenticated user may open in Analytics Workspace. When the link is opened, Splunk executes attacker‑controlled Search Processing Language (SPL) under the authenticated user’s permissions. This grants the attacker the same data access and operational privileges as the user, potentially exposing sensitive data and enabling undesired actions. The vulnerability stems from insufficient validation of search data when building queries.

Affected Systems

The affected product is Splunk Enterprise. Versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are impacted. Upgrading these installations to the specified patched releases removes the flaw.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact if exploited. The EPSS score is not available, so the current exploitation probability cannot be quantified accurately, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an unauthenticated attacker to phish an authenticated user into opening a malicious link; thus successful exploitation depends on social engineering attempts rather than automated exploitation.

Generated by OpenCVE AI on August 20, 2026 at 10:51 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

The vulnerability affects instances with Splunk Web turned on. Turning Splunk Web off is a possible workaround. See [Disable unnecessary Splunk Enterprise components](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/install-splunk-enterprise-securely/disable-unnecessary-splunk-enterprise-components) and the [web.conf](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/configuration-file-reference/10.2.0-configuration-file-reference/web.conf) configuration specification file for more information on turning off Splunk Web.


OpenCVE Recommended Actions

  • Apply the official patch by upgrading Splunk Enterprise to the latest supported release (10.4.2, 10.2.6, 10.0.9, or 9.4.14 or higher).
  • If upgrading immediately is not feasible, temporarily disable Splunk Web to prevent exploitation until a patch is applied.
  • Educate users about phishing risks and enforce click‑through protection, such as safe browsing or URL scanning, to reduce accidental exposure.

Generated by OpenCVE AI on August 20, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Analytics Workspace. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions available to that user. The vulnerability is possible because Analytics Workspace does not sufficiently validate data used to build searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will.
Title SPL Injection through Splunk Web in Splunk Enterprise
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:58.254Z

Reserved: 2026-08-19T12:02:03.627Z

Link: CVE-2026-76332

cve-icon Vulnrichment

Updated: 2026-08-27T16:17:32.049Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:17.550

Modified: 2026-08-27T17:20:14.753

Link: CVE-2026-76332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation