PT-2026-78755 · Splunk · Splunk Enterprise

CVE-2026-76328

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

6.7

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.1 Splunk Enterprise versions prior to 10.2.6 Splunk Enterprise versions prior to 10.0.9 Splunk Enterprise versions prior to 9.4.14
Description Splunk Web fails to sufficiently validate dashboard content before processing PDF exports. This allows a user with the "power" role to store malicious Search Processing Language (SPL) within a dashboard. If another authenticated user exports that dashboard as a PDF, the injected SPL executes with the permissions of the exporting user, potentially allowing unauthorized access to or modification of their data. Exploitation requires the attacker to phish the target user into initiating the request via their browser.
Recommendations Update to version 10.4.1 or later. Update to version 10.2.6 or later. Update to version 10.0.9 or later. Update to version 9.4.14 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76328

Affected Products

Splunk Enterprise