Privilege Escalation Issue in Splunk Enterprise by Splunk
CVE-2026-76350
8.8HIGH
What is CVE-2026-76350?
An issue in Splunk Enterprise allows users with the 'schedule_search' capability to exploit email alert actions, potentially executing arbitrary Search Processing Language (SPL) commands with elevated privileges. This occurs when the search scheduler incorrectly uses a system-level authentication context, compromising data integrity and system availability. Users should be aware that affected versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable, enabling unauthorized access to sensitive information through misconfigured alert settings.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9