Arbitrary SPL Code Injection in Splunk Enterprise by Non-Admin Users
CVE-2026-76339

5.4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76339?

In specific versions of Splunk Enterprise, an attacker can perform an arbitrary code injection via the geostats command by convincing a lower-privileged user to execute a malicious SPL command. This command runs with the authenticated user's privileges, allowing potential exposure of sensitive data, including stored credentials, and unauthorized modifications to lookup files. The vulnerability stems from inadequate input validation within the geostats command, which necessitates a phishing attempt to successfully exploit the flaw.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.