Security Flaw in Splunk Enterprise Compromises User Permissions
CVE-2026-76349
6.4MEDIUM
What is CVE-2026-76349?
In certain versions of Splunk Enterprise, an issue allows unauthenticated users to exploit authenticated user permissions. Attackers can manipulate crafted URLs to initiate unauthorized Search Processing Language (SPL) commands, granting access to sensitive data as if they were the authenticated user. This security flaw hinges on the inadequate handling of form token values in the URL, fostering a phishing method where users may inadvertently execute harmful commands. This vulnerability is not present in versions 10.4 and above.
Affected Version(s)
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9
Splunk Enterprise 9.4 < 9.4.14