Search Processing Language Vulnerability in Splunk Enterprise by Splunk
CVE-2026-76341

5.4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76341?

In Splunk Enterprise, certain older versions contain a flaw allowing users with the 'power' role to store malicious Search Processing Language (SPL) in datasets shared through the Table Editor. When an 'admin' user subsequently opens this dataset, the embedded SPL executes with the permissions of the admin, potentially exposing sensitive data or allowing for unwanted modifications on the search head. This vulnerability arises from insufficient safeguards in the Table Editor when preparing initial dataset data. Attackers can exploit this weakness through phishing tactics, misleading users into executing requests within their browsers.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.