Sceawere

Vulnerability Detail

CVE-2026-76327UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Splunk Secure Gateway SPL Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
Splunk
Product
Splunk Enterprise
Attack Type
The application generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a crafted Splunk Web Uniform Resource Locator (URL). The resulting dashboard searches could run arbitrary Search Processing Language (SPL) commands with the permissions available to the affected user. The commands could expose all relevant data available to that user and affect search results or lookup data. The vulnerability is possible because Splunk Secure Gateway dashboards do not correctly neutralize caller-supplied values before using them in dashboard searches. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-08-19T22:17:16.900Z",
  "pubdate": "2026-08-19T22:17:16.900Z",
  "executiveSummary": "A vulnerability exists in Splunk Enterprise and Splunk Secure Gateway that allows an unauthenticated remote attacker to execute arbitrary Search Processing Language (SPL) commands by exploiting improper input neutralization within dashboard searches. The flaw affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70.\nSuccessful exploitation requires user interaction via a phishing vector, where an unauthenticated attacker tricks a privileged user holding the admin or sc_admin Splunk roles into clicking a crafted Splunk Web Uniform Resource Locator (URL).\nUpon execution, the resulting dashboard searches run arbitrary SPL commands with the elevated privileges of the targeted user. This leads to severe security implications, including the exposure of sensitive data accessible to the administrator and the unauthorized modification or corruption of search results and lookup data.\nAlthough the attacker cannot exploit the vulnerability completely at will due to the prerequisite of user phishing, the potential impact on confidentiality and integrity within the affected Splunk deployment remains high given the administrative privilege level involved.",
  "technicalDetails": "The vulnerability stems from insufficient neutralization of caller-supplied values within Splunk Secure Gateway dashboards before those values are utilized in backend dashboard searches. The vulnerable component is the Splunk Secure Gateway application integrated within Splunk Enterprise.\nThe attack vector is network-based but strictly requires a social engineering component. An unauthenticated attacker must craft a malicious Splunk Web Uniform Resource Locator (URL) and induce an authenticated user holding the admin or sc_admin roles to open the link within their browser via phishing.\nThe step-by-step attack flow proceeds as follows: First, the attacker constructs a specially crafted Uniform Resource Locator (URL) targeting the vulnerable Splunk Secure Gateway dashboard functionality. Second, the attacker delivers this Uniform Resource Locator (URL) to a privileged user with admin or sc_admin privileges using phishing techniques. Third, the victim opens the crafted Uniform Resource Locator (URL) in their browser while authenticated to Splunk Web, initiating a request to the application. Fourth, the Splunk Secure Gateway processes the caller-supplied values without proper sanitization or neutralization. Fifth, these unsanitized values are dynamically interpolated into dashboard search queries. Finally, the search engine executes the resulting payload as arbitrary Search Processing Language (SPL) commands.\nBecause the payload executes in the security context of the victimized user, the commands inherit the full administrative privileges of the admin or sc_admin roles. The post-exploitation impact includes the unauthorized disclosure of all relevant data accessible to the administrative user, as well as the manipulation, corruption, or destruction of search results and underlying lookup data across the enterprise deployment."
}
CVE-2026-76327: Splunk Secure Gateway SPL Injection Vulnerability (MEDIUM Severity, CVSS: 6.4) - Sceawere