CVE-2026-76331: SPL Injection through the REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject Search Processing Language (SPL) into saved-search dispatch requests. This could allow for unauthorized access to all relevant data and affect system integrity within Splunk Enterprise. The vulnerability is possible because Splunk Enterprise does not correctly validate caller-supplied time values before using them in saved-search dispatch. For more information see Search endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/rest-api-reference/10.2/search-endpoints/search-endpoint-descriptions) in the Splunk documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.2 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.6 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.14
Event History
Frequently Asked Questions
Which users can exploit this issue?
A user who does not hold the Splunk "admin" or "power" role can exploit it. Exploitation requires that the user can submit saved-search dispatch requests through the REST API.
What does an attacker need to manipulate?
The attacker supplies crafted time values in a saved-search dispatch request. Splunk Enterprise does not correctly validate those caller-supplied values before using them, enabling SPL injection.
What is the impact of successful exploitation?
Successful exploitation can provide unauthorized access to all relevant data and can affect system integrity within Splunk Enterprise. Availability is not identified as impacted by the provided severity vector.
Which versions are affected?
Affected versions are Splunk Enterprise releases below 10.4.2, 10.2.6, 10.0.9, and 9.4.14.