Junglewise Threat Intelligence

CVE-2026-76388: Splunk Enterprise Security privilege escalation through search macro permissions

CVE-2026-76388 · Severity: high · CVSS 8.1 · Published 2026-08-19

Vendors: Splunk.

Executive brief

Splunk Enterprise Security is a security analytics platform used to detect and respond to threats in enterprise environments. A flaw in the User and Entity Behavior Analytics (UEBA) component allows users with the analyst role to modify search macros that run with administrator permissions, giving them unauthorized access to sensitive data and the ability to alter system behavior. This could enable attackers with analyst credentials to escalate privileges and compromise security operations.

Technical details

The vulnerability is a privilege escalation flaw (CWE-732: Improper Permission Assignment) in Splunk Enterprise Security versions below 8.6.1. The UEBA app metadata incorrectly grants analyst roles (specifically ess_analyst) write access to search macros that should be restricted to administrators only. An authenticated user with the ess_analyst role can modify these search macros, which are subsequently executed by scheduled searches running under administrator permissions. This allows an attacker to inject malicious code or queries that execute with elevated privileges, gaining access to all data and system integrity available to those searches. The attack requires valid Splunk credentials with the analyst role but no additional user interaction. The fix is to upgrade to Splunk Enterprise Security 8.6.1 or higher.

Affected products

  • Splunk Enterprise Security below 8.6.1

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Splunk Enterprise Security 8.6.1 released

References

Related threats