PT-2026-78766 · Splunk · Splunk Enterprise
CVE-2026-76339
·
Published
2026-08-19
·
Updated
2026-08-26
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.4.2
Splunk Enterprise versions prior to 10.2.6
Splunk Enterprise versions prior to 10.0.9
Splunk Enterprise versions prior to 9.4.14
Description
Insufficient input validation in the
geostats command allows a user without admin or power roles to inject arbitrary Search Processing Language (SPL) commands. This issue can be exploited by tricking an authenticated user into initiating a malicious request via phishing in Splunk Web. The injected SPL executes with the permissions of the victim user, potentially exposing sensitive data, including stored credentials, and allowing the modification of lookup files that the victim has permission to change.Recommendations
Update to version 10.4.2 or later.
Update to version 10.2.6 or later.
Update to version 10.0.9 or later.
Update to version 9.4.14 or later.
As a temporary mitigation, restrict the use of the
geostats command for users without administrative privileges.Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise