CVE-2026-76321: SPL Injection through Nearby Event Searches in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could inject arbitrary Search Processing Language (SPL) into requests that search for events near a selected event. This could allow for unauthorized search execution. The vulnerability is possible because Splunk Web does not consistently escape caller-supplied values when it builds SPL for nearby-event searches, and embedded report access accepts those requests without the expected authorization check. For more information see Use time to find nearby events (https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.2/specify-time-ranges/use-time-to-find-nearby-events) in the Splunk documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.2 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.6 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.14
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated user can exploit the issue by sending crafted requests for nearby-event searches. Exploitation does not require user interaction or prior privileges.
What functionality must be exposed for exploitation?
The issue involves Splunk Web requests that search for events near a selected event, including embedded report access that accepts those requests without the expected authorization check. Systems exposing this functionality to untrusted users are relevant to triage.
Which versions require remediation?
Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected. Upgrade to the applicable listed version or later.
What can an attacker do if exploitation succeeds?
An attacker can inject arbitrary SPL into nearby-event search requests, resulting in unauthorized search execution. The stated impact includes limited confidentiality, integrity, and availability effects.