CVE-2026-76332
Received Received - Intake

Splunk Enterprise SPL Injection via Analytics Workspace

Vulnerability report for CVE-2026-76332, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Analytics Workspace. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions available to that user. The vulnerability is possible because Analytics Workspace does not sufficiently validate data used to build searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
splunk splunk_enterprise 9.4.14
splunk splunk_enterprise 10.0.9
splunk splunk_enterprise 10.2.6
splunk splunk_enterprise to 10.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 allows an unauthenticated attacker to trick an authenticated user into opening a malicious link. When opened, the link executes attacker-controlled Search Processing Language (SPL) commands using the authenticated user's permissions. The issue stems from insufficient validation of data used to build searches in Analytics Workspace.

Impact Analysis

An attacker could exploit this to access sensitive data or perform actions available to the authenticated user, such as querying databases, modifying configurations, or exporting data. The attack requires social engineering, as the victim must be tricked into clicking the crafted link.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Organizations using affected Splunk versions may face regulatory penalties or reputational damage if exploited.

Mitigation Strategies

Upgrade Splunk Enterprise to a patched version (10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later) to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76332. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart