PT-2026-78766 · Splunk · Splunk Enterprise

CVE-2026-76339

·

Published

2026-08-19

·

Updated

2026-08-26

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.2 Splunk Enterprise versions prior to 10.2.6 Splunk Enterprise versions prior to 10.0.9 Splunk Enterprise versions prior to 9.4.14
Description Insufficient input validation in the geostats command allows a user without admin or power roles to inject arbitrary Search Processing Language (SPL) commands. This issue can be exploited by tricking an authenticated user into initiating a malicious request via phishing in Splunk Web. The injected SPL executes with the permissions of the victim user, potentially exposing sensitive data, including stored credentials, and allowing the modification of lookup files that the victim has permission to change.
Recommendations Update to version 10.4.2 or later. Update to version 10.2.6 or later. Update to version 10.0.9 or later. Update to version 9.4.14 or later. As a temporary mitigation, restrict the use of the geostats command for users without administrative privileges.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76339

Affected Products

Splunk Enterprise