Executive brief
Splunk Enterprise's Table Editor feature failed to apply security protections against risky Search Processing Language (SPL) commands when processing dataset edits. A user with "power" role privileges could embed malicious commands in a shared dataset that execute with "admin" privileges when another administrator opens it, potentially exposing sensitive data or modifying system lookup files. The attack requires social engineering to trick an admin into opening a malicious dataset.
Technical details
The vulnerability is a safeguards bypass (CWE-862) in Splunk Enterprise's Table Editor component. The Table Editor fails to apply SPL command safeguards to the field-summary search executed during the Initial Data step when processing datasets. A user with "power" role can craft and share a dataset containing risky SPL commands that execute with the privileges of the admin user who opens the dataset in the Table Editor. The attack requires phishing/social engineering to induce the admin to initiate the request. Patches are available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
Affected products
- Splunk Enterprise 10.4.0–10.4.1, 10.2.0–10.2.5, 10.0.0–10.0.8, 9.4.0–9.4.13
Timeline
- 2026-08-19: disclosed: CVE-2026-76342 published by Splunk
- 2026-08-19: patched: Fixed in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, 9.4.14