CVE-2026-76328: SPL Injection through Splunk Web in Splunk Enterprise

Published Aug 19, 2026
·
Updated

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a dashboard. When another authenticated user exports the dashboard as a Portable Document Format (PDF) file, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user. The vulnerability is possible because Splunk Web does not sufficiently validate dashboard content before processing PDF exports. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see Generate PDFs of your reports and dashboards (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.4/report-management/generate-pdfs-of-your-reports-and-dashboards) in the Splunk documentation.

Affected Software

1 affected component
Splunk Splunk Enterprise<10.4.1, =10.2.6, =10.0.9, =9.4.14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.4.2
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.2.6
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.9
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 9.4.14

Event History

Aug 19, 2026
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Splunk Enterprise deployments below 10.4.1, 10.2.6, 10.0.9, and 9.4.14 are affected when a user with the power role can save dashboard content and another authenticated user can export that dashboard to PDF.

2

What must an attacker do to exploit it?

The attacker needs the power Splunk role to store attacker-controlled SPL in a dashboard. They must then trick an authenticated target user into initiating a browser request that exports the dashboard as a PDF; the attacker cannot exploit the issue at will.

3

What is the impact on the user who exports the PDF?

Injected SPL runs with the exporting user's permissions. It can access or modify data that the exporting user is authorized to access.

4

How can we reduce risk before patching?

Limit assignment of the power role and avoid exporting dashboards to PDF when the dashboard content may have been created or modified by untrusted power-role users. Treat requests to export dashboards as potentially phishing-driven, particularly for users with broad data permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203