Executive brief
Splunk Enterprise is an analytics platform that indexes and searches large volumes of machine-generated data. A flaw in how Splunk validates user input to saved-search requests allows unprivileged users to inject arbitrary search commands, potentially exposing sensitive data and compromising system integrity. Organizations running affected versions should upgrade immediately to patch this vulnerability.
Technical details
This is a Search Processing Language (SPL) injection vulnerability in Splunk Enterprise's REST API endpoints for saved-search dispatch. The root cause is insufficient input validation on caller-supplied time values used in saved-search requests. An authenticated user without admin or power roles can inject arbitrary SPL commands into these requests. Successful exploitation allows unauthorized access to all data indexed in Splunk and can affect system integrity. The vulnerability requires network access and valid authentication credentials (low-privilege user account); no additional user interaction is needed. Splunk has released patches in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
Affected products
- Splunk Enterprise 10.4.0-10.4.1, 10.2.0-10.2.5, 10.0.0-10.0.8, 9.4.0-9.4.13
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Patches released in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14