Junglewise Threat Intelligence

CVE-2026-76332: Splunk Enterprise SPL injection through Analytics Workspace

CVE-2026-76332 · Severity: high · CVSS 7.1 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise, a widely-used data analytics platform, contains a vulnerability in its Analytics Workspace feature that allows an attacker to inject malicious search commands. An unauthenticated attacker can craft a link that, when opened by a legitimate user, executes attacker-controlled queries with the victim's permissions, potentially exposing sensitive data or performing unauthorized actions. This requires social engineering to trick a user into clicking the malicious link.

Technical details

CVE-2026-76332 is an SPL (Search Processing Language) injection vulnerability in Splunk Enterprise's Analytics Workspace triggered through insufficient validation of search-building parameters. The vulnerability is classified as CWE-20 (improper input validation). An attacker crafts a malicious link containing injected SPL code that executes in the context of an authenticated user's session when they open it. The attack requires social engineering (phishing) to trick a user into clicking the link; unauthenticated attackers cannot exploit it directly or at will. Affected versions are below 10.4.2, 10.2.6, 10.0.9, and 9.4.14; patches are available by upgrading to these versions or later.

Affected products

  • Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched

References