CVE-2026-76314: The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. in Splunk Splunk Enterprise
Description
CVE-2026-76314 is a high-severity vulnerability in Splunk Enterprise that allows a user without admin or power roles to perform remote code execution by submitting crafted Splunk Web Manager Configuration content. This occurs in versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 due to insufficient input validation of Extensible Markup Language expressions and improper access control on configuration routes.
CVSS v3.1
Score 8.8high
Affected software
Splunk
Splunk Enterprise
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Splunk Enterprise versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a vulnerability exists where Splunk Web evaluates manager XML expressions without adequate input restrictions. Additionally, the configuration route does not enforce the expected capability requirements for manager configuration changes. This allows users lacking admin or power roles to submit specially crafted configuration content that leads to remote code execution, compromising system integrity, confidentiality, and availability.
Potential Impact
An attacker with limited privileges (not admin or power roles) can execute arbitrary code remotely on the affected Splunk Enterprise system. This can lead to full compromise of the system, including unauthorized access to all relevant data and disruption of system availability.
Mitigation Recommendations
Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later, where this vulnerability is fixed. These versions implement proper input validation and enforce correct capability requirements for manager configuration changes. No other mitigation is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2026-08-19T12:02:03.625Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a862251acd9273b49a6fdab
Added to database: 08/19/2026, 21:38:25 UTC
Last enriched: 09/11/2026, 04:32:12 UTC
Last updated: 10/04/2026, 10:04:21 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.