PT-2026-78727 · Splunk · Splunk Enterprise
CVE-2026-76255
·
Published
2026-08-19
·
Updated
2026-08-21
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.4.1
Splunk Enterprise versions prior to 10.2.6
Splunk Enterprise versions prior to 10.0.8
Splunk Enterprise versions prior to 9.4.13
Description
A user without admin or power roles can trick another user into executing arbitrary Search Processing Language (SPL) commands via the Data Model Editor. This occurs because Splunk Web fails to apply SPL safeguards for risky commands when the Data Model Editor performs a base search for auto-extracted fields. An attacker must phish the target user to initiate the request in their browser. Successful exploitation allows the attacker to access data available to the affected user and potentially compromise system integrity.
Recommendations
Update to version 10.4.1 or later.
Update to version 10.2.6 or later.
Update to version 10.0.8 or later.
Update to version 9.4.13 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise