Junglewise Threat Intelligence

CVE-2026-76335: Splunk Enterprise remote code execution in Web Manager configuration

CVE-2026-76335 · Severity: high · CVSS 8.8 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise, a widely-used data analytics and security monitoring platform, contains a vulnerability in its Web Manager configuration feature that allows authenticated users without proper authorization to execute arbitrary operating system commands. An attacker can craft a malicious XML configuration file and, when opened in Splunk Web Manager, achieve remote code execution with the privileges of the Splunk service account, potentially compromising the entire monitoring infrastructure and any data it has access to.

Technical details

The vulnerability is a missing authorization check (CWE-94, code injection) in Splunk Enterprise's Web Manager XML configuration handler. An authenticated user without the edit_manager_xml role capability can submit malicious XML configuration changes to Splunk Web, which are executed without proper validation when the affected Web Manager page is accessed. The attack vector is network-based and requires only valid authentication credentials (not elevated privileges). An attacker can achieve remote code execution as the Splunk service user account. Affected versions are 10.4.0–10.4.1, 10.2.0–10.2.5, 10.0.0–10.0.8, and 9.4.0–9.4.13; patches are available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.

Affected products

  • Splunk Enterprise 10.4.0-10.4.1, 10.2.0-10.2.5, 10.0.0-10.0.8, 9.4.0-9.4.13

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Patches released in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14

References