Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store risky Search Processing Language (SPL) commands in a Table Editor dataset and share the dataset. A user who holds the "admin" Splunk role triggers the commands when that user opens the dataset in the Table Editor. The commands run using the permissions of the second user and could expose all relevant data and modify lookup files. The vulnerability is possible because the Table Editor does not apply SPL safeguards for risky commands to the field-summary search that it runs for the Initial Data step. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see SPL safeguards for risky commands (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/best-practices-for-splunk-platform-security/spl-safeguards-for-risky-commands) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Published: 2026-08-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Splunk Enterprise allows a user with the 'power' role to embed risky Search Processing Language (SPL) commands into a Table Editor dataset and share it. When an 'admin' role user opens the dataset, the stored commands run with the admin’s permissions, enabling the attacker to read all data available to the admin and alter lookup files. The flaw arises because the Table Editor applies SPL safeguards only to the user’s view of the dataset, not to the initial data-population query that triggers the risky commands. This results in an unintended privilege escalation that can compromise data confidentiality and integrity without executing arbitrary code. The impact is limited to scenarios where the vulnerable Splunk Web interface is enabled and where the attacker can manipulate a privileged administrator into opening a crafted dataset.

Affected Systems

All Splunk Enterprise installations running a version older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are vulnerable. The flaw requires the Splunk Web component to be active; therefore only instances that expose Splunk Web are at risk. The Table Editor, which is part of the web interface, is the attack vector. Users with the predefined 'power' role are the source of the risky commands, while users with the 'admin' role can unintentionally trigger them. To remediate, upgrade to a fixed release, disable Splunk Web if the interface is not needed, or restrict the use of the Table Editor by revoking the 'power' role from untrusted users.

Risk and Exploitability

The CVSS score of 5.4 reflects moderate severity. Because the EPSS score is not available, the likelihood of exploitation in the wild is unclear, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires social engineering: an attacker must first create a risky dataset as a power‑role user and then trick an admin into opening the dataset in their browser. This requirement reduces the attack surface compared to more direct remote code execution vulnerabilities, but the potential impact remains significant given the elevated privileges exercised upon trigger.

Generated by OpenCVE AI on August 20, 2026 at 10:49 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

The vulnerability affects instances with Splunk Web turned on. Turning Splunk Web off is a possible workaround. See [Disable unnecessary Splunk Enterprise components](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/install-splunk-enterprise-securely/disable-unnecessary-splunk-enterprise-components) and the [web.conf](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/web.conf) configuration specification file for more information on turning off Splunk Web.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to a fixed version—at least 10.4.2, 10.2.6, 10.0.9, or 9.4.14, depending on your current line.
  • If an upgrade cannot be applied immediately, permanently disable Splunk Web on the affected instance by editing web.conf or using the component disabling guide.
  • Review and restrict the ‘power’ role: ensure only trusted users can assign risky SPL commands via the Table Editor, or remove that capability from the role altogether.

Generated by OpenCVE AI on August 20, 2026 at 10:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store risky Search Processing Language (SPL) commands in a Table Editor dataset and share the dataset. A user who holds the "admin" Splunk role triggers the commands when that user opens the dataset in the Table Editor. The commands run using the permissions of the second user and could expose all relevant data and modify lookup files. The vulnerability is possible because the Table Editor does not apply SPL safeguards for risky commands to the field-summary search that it runs for the Initial Data step. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see SPL safeguards for risky commands (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/best-practices-for-splunk-platform-security/spl-safeguards-for-risky-commands) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Title Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:21:19.441Z

Reserved: 2026-08-19T12:02:03.627Z

Link: CVE-2026-76342

cve-icon Vulnrichment

Updated: 2026-08-26T14:49:41.360Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:18.890

Modified: 2026-08-26T16:16:40.860

Link: CVE-2026-76342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses