Security Flaw in Splunk Enterprise Compromises User Permissions
CVE-2026-76349

6.4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76349?

In certain versions of Splunk Enterprise, an issue allows unauthenticated users to exploit authenticated user permissions. Attackers can manipulate crafted URLs to initiate unauthorized Search Processing Language (SPL) commands, granting access to sensitive data as if they were the authenticated user. This security flaw hinges on the inadequate handling of form token values in the URL, fostering a phishing method where users may inadvertently execute harmful commands. This vulnerability is not present in versions 10.4 and above.

Affected Version(s)

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

Splunk Enterprise 9.4 < 9.4.14

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.