CVE-2026-76270: Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splunk Enterprise
In Splunk Enterprise versions below 10.4.3, a user that holds a role with the listspl2modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (REST) API, including private SPL2 module definitions belonging to other users. The vulnerability is possible because Splunk Enterprise and Splunk Cloud Platform do not parameterize user-supplied values before using them in database queries for SPL2 module filtering. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.
Splunk Enterprise versions 10.2.x, 10.0.x, and 9.4.x are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.10 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.15
Event History
Frequently Asked Questions
Which users could exploit this issue?
A user must hold a role with the list_spl2_modules capability. The attack can be performed remotely and does not require user interaction.
What could an attacker access?
An attacker could use SQL injection in SPL2 module filtering to access relevant data exposed through the affected REST API. This includes private SPL2 module definitions owned by other users.
Which Splunk Enterprise versions are affected?
Splunk Enterprise versions below 10.4.3 are affected, except that the 10.2.x, 10.0.x, and 9.4.x release lines are explicitly identified as not affected.
What can be done before upgrading?
Limit the list_spl2_modules capability to only roles that require it. Users without that capability do not meet the stated prerequisite for exploitation.