Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. When the same user opens the affected Splunk Web Manager page, Splunk Enterprise runs attacker-controlled operating-system commands as the user account running Splunk Enterprise. The vulnerability is possible because Splunk Web does not require the edit_manager_xml capability before accepting Splunk Web Manager XML configuration changes.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user who does not have the edit_manager_xml capability can supply a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. When the user opens the affected Splunk Web Manager page, the system runs attacker‑controlled operating‑system commands under the Splunk Enterprise service account. The flaw is a classic code‑execution bug (CWE‑94), allowing an attacker to execute arbitrary commands on the host that runs Splunk Enterprise.

Affected Systems

Splunk Enterprise for all versions earlier than 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable. Only instances that run the Splunk Web component are impacted, as the exploitation path relies on the Web Manager page.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is classified as high severity. The EPSS score is not available, and the flaw is not yet listed in CISA KEV, but the fact that an authenticated user can trigger OS command execution means that any user with access to the Splunk interface presents a potential entry point. The attack vector requires the attacker to be authenticated and to modify the XML configuration, but does not need any special privilege beyond non‑edit_manager_xml access, making the exploit relatively easy to carry out in a compromised environment.

Generated by OpenCVE AI on August 20, 2026 at 10:17 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

The vulnerability affects instances with Splunk Web turned on. Turning Splunk Web off is a possible workaround. See [Disable unnecessary Splunk Enterprise components](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/install-splunk-enterprise-securely/disable-unnecessary-splunk-enterprise-components) and the [web.conf](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/web.conf) configuration specification file for more information on turning off Splunk Web.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later to apply the vendor patch.
  • If Splunk Web is not required for your environment, disable it entirely as a workaround; refer to Splunk’s documentation on disabling unnecessary components.
  • Limit user privileges to prevent unauthorized XML configuration changes and enforce the edit_manager_xml capability for any staff that must edit Manager configuration.

Generated by OpenCVE AI on August 20, 2026 at 10:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. When the same user opens the affected Splunk Web Manager page, Splunk Enterprise runs attacker-controlled operating-system commands as the user account running Splunk Enterprise. The vulnerability is possible because Splunk Web does not require the edit_manager_xml capability before accepting Splunk Web Manager XML configuration changes.
Title Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:58.589Z

Reserved: 2026-08-19T12:02:03.627Z

Link: CVE-2026-76335

cve-icon Vulnrichment

Updated: 2026-08-27T16:17:37.046Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:17.973

Modified: 2026-08-27T17:20:15.697

Link: CVE-2026-76335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:30:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')