PT-2026-78727 · Splunk · Splunk Enterprise

CVE-2026-76255

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.1 Splunk Enterprise versions prior to 10.2.6 Splunk Enterprise versions prior to 10.0.8 Splunk Enterprise versions prior to 9.4.13
Description A user without admin or power roles can trick another user into executing arbitrary Search Processing Language (SPL) commands via the Data Model Editor. This occurs because Splunk Web fails to apply SPL safeguards for risky commands when the Data Model Editor performs a base search for auto-extracted fields. An attacker must phish the target user to initiate the request in their browser. Successful exploitation allows the attacker to access data available to the affected user and potentially compromise system integrity.
Recommendations Update to version 10.4.1 or later. Update to version 10.2.6 or later. Update to version 10.0.8 or later. Update to version 9.4.13 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76255

Affected Products

Splunk Enterprise