CVE-2026-76322: SPL Injection through Dashboard Studio Search Query Options in Splunk Enterprise

Published Aug 19, 2026
·
Updated

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user" Splunk role could craft a Dashboard Studio dashboard that runs attacker-controlled Search Processing Language (SPL) for another authenticated user. The attacker-controlled SPL could access all relevant data and affect system integrity and availability. The vulnerability is possible because Dashboard Studio does not consistently enforce the expected app-visibility authorization boundary before dashboard search query options reach search dispatch. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "user" Splunk role should not be able to exploit the vulnerability at will. For more information see Create search-based visualizations with ds.search (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/dashboard-studio/10.4/use-data-sources/create-search-based-visualizations-with-ds.search) in the Splunk documentation.

Affected Software

1 affected component
Splunk Splunk Enterprise<10.4.2, <10.2.6, <10.0.9, <9.4.14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.4.2
  2. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.2.6
  3. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 10.0.9
  4. Upgrade

    Upgrade Splunk Enterprise to a version that resolves this vulnerability.

    Fixed in 9.4.14

Event History

Aug 19, 2026
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who is exposed?

An attacker needs a Splunk account with the "user" role and must be able to create a Dashboard Studio dashboard. The target must be an authenticated Splunk user who can be tricked into initiating a request in their browser.

2

Does exploitation require user interaction?

Yes. The attacker must phish the affected user into initiating a request in their browser; a user with the "user" role cannot exploit the issue at will.

3

What access could attacker-controlled SPL obtain?

The attacker-controlled SPL could access all relevant data available in the affected context and could affect system integrity and availability.

4

Which Splunk Enterprise releases are affected?

Affected releases are versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Upgrading to the applicable listed release addresses the affected version range.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203