Description
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the scheduled searches that run for that user. The vulnerability is possible because the Analyst Queue search filter handling does not validate filter field names before the fields are included in SPL searches. For more information see Users and roles for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/install/8.4/installation/users-and-roles-for-splunk-enterprise-security), Manage analyst workflows using the analyst queue in Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.4/mission-control/manage-analyst-workflows-using-the-analyst-queue-in-splunk-enterprise-security), and Overview of Mission Control in Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.5/mission-control/overview-of-mission-control-in-splunk-enterprise-security) in the Splunk documentation.
Published: 2026-08-19
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user who holds a role containing the mc_investigation_read capability in Splunk Enterprise Security versions earlier than 8.6.1 can inject arbitrary Search Processing Language (SPL) through the Analyst Queue REST API. The Analyst Queue filter handling fails to validate filter field names before including them in SPL searches, allowing the attacker to execute malicious SPL commands. This flaw can reveal sensitive data and modify scheduled searches, thereby compromising confidentiality, integrity, and availability of the system. The weakness is an input validation failure, classified as CWE-20.

Affected Systems

The vulnerability affects Splunk Enterprise Security deployments running any version older than 8.6.1. Only the Splunk Enterprise Security product is impacted; other Splunk products are not listed as affected.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS scores are not available, and the vulnerability is not in the CISA KEV catalog, so no current evidence of widespread exploitation is documented. Exploitation requires authenticated access to the Splunk Enterprise Security REST API with a role that includes mc_investigation_read, implying an internal attacker or a compromised privileged user. If such a user submits crafted search filter parameters, the attacker can run arbitrary SPL within the context of the scheduled searches, potentially accessing or altering all data accessible to that user.

Generated by OpenCVE AI on August 20, 2026 at 10:36 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise Security to 8.6.1 or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise Security to version 8.6.1 or later.
  • Revoke or restrict the mc_investigation_read capability from roles that use the Analyst Queue, limiting the attack surface for SPL injection.
  • Implement or enable input validation on Analyst Queue search filter inputs and monitor API traffic for suspicious SPL strings, logging and alerting on anomalies.

Generated by OpenCVE AI on August 20, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:splunk:enterprise_security:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk enterprise Security
Vendors & Products Splunk
Splunk enterprise Security

Thu, 20 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the scheduled searches that run for that user. The vulnerability is possible because the Analyst Queue search filter handling does not validate filter field names before the fields are included in SPL searches. For more information see Users and roles for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/install/8.4/installation/users-and-roles-for-splunk-enterprise-security), Manage analyst workflows using the analyst queue in Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.4/mission-control/manage-analyst-workflows-using-the-analyst-queue-in-splunk-enterprise-security), and Overview of Mission Control in Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.5/mission-control/overview-of-mission-control-in-splunk-enterprise-security) in the Splunk documentation.
Title SPL Injection through the REST API in Splunk Enterprise Security
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Splunk Enterprise Security
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-21T03:55:19.756Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76387

cve-icon Vulnrichment

Updated: 2026-08-20T13:17:30.251Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:24.953

Modified: 2026-08-25T16:30:13.913

Link: CVE-2026-76387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:30Z

Weaknesses
  • CWE-20

    Improper Input Validation