In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role… (CVE-2026-76329)
Description
Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 contain a vulnerability where an unauthenticated attacker can trick an admin user into opening a crafted Monitoring Console link. This causes the system to execute attacker-controlled Search Processing Language (SPL) commands with the admin user's permissions. The flaw arises from insufficient validation of data used in dashboard searches. Exploitation requires phishing the admin user to open the malicious link, and the attacker cannot exploit the vulnerability without user interaction.
CVSS v3.1
Score 6.4medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76329 affects Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The vulnerability allows an unauthenticated attacker to craft a Monitoring Console link that, when opened by a user with the admin role, causes Splunk to run attacker-controlled SPL commands with that user's privileges. This occurs due to inadequate validation of data used to build dashboard searches in the Monitoring Console. The attacker must phish the admin user to open the link, as exploitation requires user interaction. The SPL injection can lead to exposure of data accessible to the admin user or modification of lookup data.
Potential Impact
Successful exploitation can lead to unauthorized disclosure of data accessible to the admin user and limited modification of lookup data. The vulnerability requires user interaction and high attack complexity, limiting exploitability. There is no indication of active exploitation in the wild. The impact on confidentiality is high, integrity impact is low, and availability impact is low.
Mitigation Recommendations
No official patch or fix information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should be cautious about opening links from untrusted sources, especially those that lead to the Monitoring Console. Educate admin users to recognize phishing attempts involving crafted links targeting Splunk dashboards.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4hw2-8jm2-9j36
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-76329"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a870a90acd9273b49b5a1cc
Added to database: 08/20/2026, 14:09:20 UTC
Last enriched: 08/20/2026, 14:52:46 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 38
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.