Executive brief
Splunk Enterprise Security is a security monitoring and analytics platform used by enterprises to detect and respond to threats. A flaw in versions before 8.6.1 allows users with investigation capabilities to inject malicious search commands through Analyst Queue filters, bypassing validation checks and gaining unauthorized access to sensitive data and system integrity that scheduled searches can reach.
Technical details
This is a Search Processing Language (SPL) injection vulnerability in Splunk Enterprise Security's Analyst Queue feature (CWE-20: Improper Input Validation). The vulnerability exists because the search filter handling in the Analyst Queue does not validate filter field names before incorporating them into SPL search queries. An authenticated attacker with the mc_investigation_read capability can inject arbitrary SPL commands through unvalidated filter fields, executed with the permissions of the scheduled search context. This allows unauthorized access to data and modification of system state available to those searches. The vulnerability is network-accessible and requires only valid user credentials (low privilege required). Splunk released a fix in version 8.6.1.
Affected products
- Splunk Enterprise Security below 8.6.1
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fix available in version 8.6.1