No analysis available yet.
Vendor Solution
Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.
Vendor Workaround
Turn off the PostgreSQL sidecar service by setting disabled = true in the [postgres] stanza in the server.conf configuration file if you do not use Edge Processor, OpAmp, or Search Processing Language 2 (SPL2) data pipelines. For more information see [Sidecar configuration settings](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation. Note: Turning off the PostgreSQL sidecar service breaks these features and can affect dependent sidecar processes.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0801 |
|
Wed, 19 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint, allowing for access to substantially all data stored by Data Orchestration, including jobs owned by other users and stored connection credentials. The vulnerability is possible because Data Orchestration builds a database query from user-controlled job filter values without using parameterized queries. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation. | |
| Title | Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-08-19T21:34:40.632Z
Reserved: 2026-08-19T12:02:03.627Z
Link: CVE-2026-76343
No data.
Status : Received
Published: 2026-08-19T22:17:19.023
Modified: 2026-08-19T22:17:19.023
Link: CVE-2026-76343
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')