Search Processing Language Vulnerability in Splunk Enterprise by Splunk
CVE-2026-76341
5.4MEDIUM
What is CVE-2026-76341?
In Splunk Enterprise, certain older versions contain a flaw allowing users with the 'power' role to store malicious Search Processing Language (SPL) in datasets shared through the Table Editor. When an 'admin' user subsequently opens this dataset, the embedded SPL executes with the permissions of the admin, potentially exposing sensitive data or allowing for unwanted modifications on the search head. This vulnerability arises from insufficient safeguards in the Table Editor when preparing initial dataset data. Attackers can exploit this weakness through phishing tactics, misleading users into executing requests within their browsers.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9