Junglewise Threat Intelligence

CVE-2026-76350: Splunk Enterprise privilege escalation in scheduled search alert actions

CVE-2026-76350 · Severity: high · CVSS 8.8 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise, a widely-used data analytics and monitoring platform, contains a privilege escalation vulnerability in its scheduled search alert feature. A user with basic scheduling permissions can configure PDF email alerts that execute with system-level privileges, allowing them to run arbitrary commands, expose sensitive data, and potentially compromise the entire search head infrastructure.

Technical details

The vulnerability is a privilege escalation flaw (CWE-269) in how Splunk Enterprise handles authentication context during PDF attachment rendering in email alert actions. When a scheduled search triggers an email alert with PDF attachments, the search scheduler incorrectly passes a system-level authentication context to the alert action instead of the action owner's context. This allows a user holding the schedule_search capability to execute arbitrary SPL (Search Processing Language) commands with elevated privileges. The attack requires the attacker to have schedule_search capability but no administrative role. The vulnerability affects versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14; patches are available.

Affected products

  • Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, and 9.4.14

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Patches released in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14

References