Sceawere

Vulnerability Detail

CVE-2026-76316UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Splunk Enterprise SPL Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Splunk
Product
Splunk Enterprise
Attack Type
The application generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port could store a Search Processing Language (SPL) pipeline that runs when an administrator opens the Add Data forwarder workflow. The SPL pipeline could access all relevant data, affect system integrity, and affect availability of the Splunk platform instance. The SPL injection is possible because Deployment Server client identifiers are placed into dispatched searches without neutralizing special characters. Successful exploitation requires an administrator to open the affected Add Data forwarder workflow after the unauthenticated user registers a crafted Deployment Server client identity. For more information see Forward data (https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/10.2/how-to-get-data-into-your-splunk-deployment/forward-data) and About agent management (https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/10.4/agent-management/about-agent-management) in the Splunk documentation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-19T22:17:15.500Z",
  "pubdate": "2026-08-19T22:17:15.500Z",
  "executiveSummary": "An unauthenticated SPL injection vulnerability exists in Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14.\nThe vulnerability allows an unauthenticated attacker who can reach the Splunk management port to store a malicious Search Processing Language pipeline.\nSuccessful exploitation requires user interaction, specifically an administrator opening the Add Data forwarder workflow after a crafted Deployment Server client identity is registered.\nThe impact includes unauthorized access to all relevant data, potential compromise of system integrity, and degradation or loss of platform availability.\nRisk implications are severe due to the potential exposure of sensitive organizational data and administrative escalation vectors triggered during standard management workflows.",
  "technicalDetails": "The root cause of the vulnerability is the improper neutralization of special characters when Deployment Server client identifiers are dynamically inserted into dispatched searches.\nNetwork exposure involves accessibility to the Splunk management port by unauthenticated users, requiring no prior authentication or administrative privileges to register the malicious payload.\nThe vulnerable component handles Deployment Server client identities and incorporates them directly into Search Processing Language pipelines without input sanitization or parameterization.\nThe attack flow begins when an unauthenticated attacker registers a crafted Deployment Server client identity containing malicious Search Processing Language syntax via the exposed management port.\nThe crafted pipeline is stored within the system as part of the client identifier registration process.\nSubterior exploitation occurs asynchronously when a high-privileged administrator navigates to and opens the Add Data forwarder workflow.\nUpon opening the workflow, the stored Search Processing Language pipeline executes within the administrative context.\nPayload execution allows unauthorized access to all relevant operational data accessible by the administrative user.\nFurthermore, the injected pipeline can affect system integrity and platform availability.\nAffected versions comprise Splunk Enterprise instances below 10.4.1, 10.2.5, 10.0.9, and 9.4.14."
}
CVE-2026-76316: Splunk Enterprise SPL Injection Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere