CVE-2026-76339: SPL Injection through the geostats Command in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject arbitrary Search Processing Language (SPL) commands through the geostats command. The injected SPL runs with the permissions of another authenticated user after that user initiates the attacker-controlled geostats search in Splunk Web. The injected SPL could expose all relevant data available to the second user, including stored credentials, and modify lookup files that the second user has permission to change. The vulnerability is possible because the geostats command does not sufficiently validate input before Splunk Enterprise processes it. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who does not hold the "admin" or "power" Splunk roles should not be able to exploit the vulnerability at will. For more information see geostats (https://help.splunk.com/en/splunk-enterprise/spl-search-reference/10.0/search-commands/geostats) in the Splunk documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.2 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.6 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.14
Event History
Frequently Asked Questions
Who is exposed to exploitation?
An authenticated Splunk user without the admin or power role can prepare the malicious geostats search, but exploitation also requires a second authenticated user to initiate that attacker-controlled search in Splunk Web. The impact is determined by the permissions of that second user.
What can the injected SPL do with the affected user's access?
It can expose data available to the user who runs the search, including stored credentials. It can also modify lookup files that the affected user is permitted to change.
Does exploitation require user interaction?
Yes. The attacker must phish an affected user into initiating a request in their browser, causing the attacker-controlled geostats search to run with that user's permissions. The lower-privileged attacker cannot exploit the issue at will.
Which versions are affected?
Affected versions are Splunk Enterprise releases below 10.4.2, 10.2.6, 10.0.9, and 9.4.14.