Executive brief
Splunk Enterprise, a widely-used data analytics platform, contains a vulnerability in its Analytics Workspace feature that allows an attacker to inject malicious search commands. An unauthenticated attacker can craft a link that, when opened by a legitimate user, executes attacker-controlled queries with the victim's permissions, potentially exposing sensitive data or performing unauthorized actions. This requires social engineering to trick a user into clicking the malicious link.
Technical details
CVE-2026-76332 is an SPL (Search Processing Language) injection vulnerability in Splunk Enterprise's Analytics Workspace triggered through insufficient validation of search-building parameters. The vulnerability is classified as CWE-20 (improper input validation). An attacker crafts a malicious link containing injected SPL code that executes in the context of an authenticated user's session when they open it. The attack requires social engineering (phishing) to trick a user into clicking the link; unauthenticated attackers cannot exploit it directly or at will. Affected versions are below 10.4.2, 10.2.6, 10.0.9, and 9.4.14; patches are available by upgrading to these versions or later.
Affected products
- Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched