Junglewise Threat Intelligence

CVE-2026-76330: Splunk Enterprise SPL injection in Monitoring Console forwarder filters

CVE-2026-76330 · Severity: high · CVSS 7.1 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise's Monitoring Console contains a vulnerability where an attacker can craft a malicious link that, when clicked by an authenticated user, executes attacker-controlled Search Processing Language (SPL) commands with the victim's permissions. This allows the attacker to access data, modify configurations, or perform actions as the authenticated user. While the vulnerability requires social engineering (phishing), it can lead to unauthorized data access and system manipulation within Splunk.

Technical details

CVE-2026-76330 is an SPL injection vulnerability (CWE-20: Improper Input Validation) in Splunk Enterprise's Monitoring Console forwarder dashboard search functionality. The root cause is insufficient validation of data used to construct forwarder dashboard searches. An unauthenticated attacker can craft a malicious URL containing injected SPL commands that, when visited by an authenticated user, executes the attacker's commands using the victim's privileges. The vulnerability requires user interaction (phishing/social engineering) and is not exploitable by unauthenticated users at will. Fixes are available in Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14 or higher.

Affected products

  • Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, and 9.4.14

Timeline

  • 2026-08-19: disclosed

References