Junglewise Threat Intelligence

CVE-2026-76343: Splunk Enterprise SQL injection in Data Orchestration

CVE-2026-76343 · Severity: medium · CVSS 6.5 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise is a centralized data analytics platform used by organizations to collect, index, and analyze machine data. A SQL injection vulnerability in the Data Orchestration feature allows unprivileged users to execute arbitrary database queries, potentially exposing sensitive data including credentials, job configurations, and data from other users' jobs—bypassing intended role-based access controls.

Technical details

CVE-2026-76343 is a SQL injection vulnerability (CWE-89) in the Data Orchestration jobs REST API endpoint. The vulnerability exists because user-supplied job filter values are concatenated directly into SQL queries without parameterization. An authenticated user without "admin" or "power" roles can craft malicious filter parameters to inject SQL commands. The attack is network-reachable and requires only standard user authentication (no elevated privileges). Successful exploitation allows attackers to extract all data managed by Data Orchestration, including stored connection credentials and jobs belonging to other users. Patches are available in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14.

Affected products

  • Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Patches released: 10.4.2, 10.2.6, 10.0.9, and 9.4.14

References