PT-2026-78815 · Splunk · Splunk Enterprise Security

CVE-2026-76388

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise Security versions prior to 8.6.1
Description A user with the ess analyst role can modify User and Entity Behavior Analytics (UEBA) search macros. Because these macros are used by scheduled searches that execute with administrator permissions, this allows an analyst to gain unauthorized access to sensitive data and compromise system integrity. The issue stems from UEBA app metadata incorrectly granting write access to search macros to analyst roles instead of restricting it to administrator roles.
Recommendations Update to version 8.6.1 or later.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76388

Affected Products

Splunk Enterprise Security