PT-2026-78777 · Splunk · Splunk Enterprise
CVE-2026-76350
·
Published
2026-08-19
·
Updated
2026-08-21
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.4.2
Splunk Enterprise versions prior to 10.2.6
Splunk Enterprise versions prior to 10.0.9
Splunk Enterprise versions prior to 9.4.14
Description
A user with the
schedule search capability can configure PDF attachments within the email alert action workflow. This allows the execution of arbitrary Search Processing Language (SPL) commands with system-level privileges when the email alert action runs. The issue occurs because the search scheduler uses a system-level authentication context instead of the action owner context during the rendering of PDF attachments, potentially exposing data and compromising the integrity and availability of the search head.Recommendations
Update to version 10.4.2 or later.
Update to version 10.2.6 or later.
Update to version 10.0.9 or later.
Update to version 9.4.14 or later.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise