Arbitrary SPL Code Injection in Splunk Enterprise by Non-Admin Users
CVE-2026-76339
5.4MEDIUM
What is CVE-2026-76339?
In specific versions of Splunk Enterprise, an attacker can perform an arbitrary code injection via the geostats command by convincing a lower-privileged user to execute a malicious SPL command. This command runs with the authenticated user's privileges, allowing potential exposure of sensitive data, including stored credentials, and unauthorized modifications to lookup files. The vulnerability stems from inadequate input validation within the geostats command, which necessitates a phishing attempt to successfully exploit the flaw.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9