Junglewise Threat Intelligence

CVE-2026-76329: Splunk Enterprise SPL injection through Monitoring Console dashboard inputs

CVE-2026-76329 · Severity: medium · CVSS 6.4 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise's Monitoring Console feature is vulnerable to SPL (Search Processing Language) injection when displaying dashboard information. An attacker can craft a malicious link and trick an administrator into clicking it, causing the system to execute attacker-controlled searches with the admin user's privileges. This could result in data exposure or modification of lookup tables used by the organization.

Technical details

This is an SPL injection vulnerability (CWE-943) in the Monitoring Console dashboard input validation component of Splunk Enterprise. The root cause is insufficient validation of data used to construct dashboard searches. The attack requires social engineering: an unauthenticated attacker must phish an admin user into opening a crafted link. Once clicked, the injected SPL executes with the targeted admin user's permissions, allowing the attacker to read sensitive data or modify lookup data. The vulnerability affects versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14; patches are available in these versions and higher.

Affected products

  • Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14

Timeline

  • 2026-08-19: disclosed: CVE-2026-76329 published
  • 2026-08-19: patched: Patches released for Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14

References