Risky SPL Commands Vulnerability in Splunk Enterprise by Splunk
CVE-2026-76342
5.4MEDIUM
What is CVE-2026-76342?
In Splunk Enterprise, versions prior to specified thresholds, users with the 'power' role can store hazardous Search Processing Language (SPL) commands in a Table Editor dataset and share them. When an 'admin' role user accesses this dataset, they unknowingly trigger the commands, affecting their permissions and potentially exposing sensitive data or modifying lookup files. This occurs because the Table Editor lacks adequate SPL safeguards during the dataset's initial data processing. An attacker must employ social engineering tactics to persuade the affected user to execute a request within their browser, thus exploiting the vulnerability.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9