PT-2026-78777 · Splunk · Splunk Enterprise

CVE-2026-76350

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.2 Splunk Enterprise versions prior to 10.2.6 Splunk Enterprise versions prior to 10.0.9 Splunk Enterprise versions prior to 9.4.14
Description A user with the schedule search capability can configure PDF attachments within the email alert action workflow. This allows the execution of arbitrary Search Processing Language (SPL) commands with system-level privileges when the email alert action runs. The issue occurs because the search scheduler uses a system-level authentication context instead of the action owner context during the rendering of PDF attachments, potentially exposing data and compromising the integrity and availability of the search head.
Recommendations Update to version 10.4.2 or later. Update to version 10.2.6 or later. Update to version 10.0.9 or later. Update to version 9.4.14 or later.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76350

Affected Products

Splunk Enterprise