PT-2026-78815 · Splunk · Splunk Enterprise Security
CVE-2026-76388
·
Published
2026-08-19
·
Updated
2026-08-21
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise Security versions prior to 8.6.1
Description
A user with the
ess analyst role can modify User and Entity Behavior Analytics (UEBA) search macros. Because these macros are used by scheduled searches that execute with administrator permissions, this allows an analyst to gain unauthorized access to sensitive data and compromise system integrity. The issue stems from UEBA app metadata incorrectly granting write access to search macros to analyst roles instead of restricting it to administrator roles.Recommendations
Update to version 8.6.1 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise Security