Sceawere

Vulnerability Detail

CVE-2026-76328UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Splunk Enterprise Stored SPL Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.7
Creation Date
2h ago
Vendor
Splunk
Product
Splunk Enterprise
Attack Type
The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
Attack Complexity
HIGH

Narrative and Response

Description

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a dashboard. When another authenticated user exports the dashboard as a Portable Document Format (PDF) file, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user. The vulnerability is possible because Splunk Web does not sufficiently validate dashboard content before processing PDF exports. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see Generate PDFs of your reports and dashboards (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.4/report-management/generate-pdfs-of-your-reports-and-dashboards) in the Splunk documentation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.7",
  "pubDate": "2026-08-19T22:17:17.033Z",
  "pubdate": "2026-08-19T22:17:17.033Z",
  "executiveSummary": "A stored Search Processing Language (SPL) injection vulnerability exists in Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14.\nThe vulnerability allows an authenticated user assigned the 'power' Splunk role to store attacker-controlled SPL commands within a dashboard.\nWhen a victim user exports the affected dashboard as a Portable Document Format (PDF) file, Splunk Enterprise executes the injected SPL using the security context and permissions of the exporting user.\nThe primary impact involves unauthorized access to or modification of data accessible to the exporting user, depending on their specific privileges within the system.\nExploitation requires the attacker to successfully phish the victim user, tricking them into initiating a request via their browser to export the malicious dashboard.\nConsequently, the attacker holding the 'power' role cannot exploit the vulnerability entirely at will without user interaction.\nThe flaw stems from insufficient validation of dashboard content by Splunk Web prior to initiating PDF generation and processing.",
  "technicalDetails": "The vulnerability resides within Splunk Web, specifically in the component responsible for processing dashboard content and generating Portable Document Format (PDF) exports.\nThe root cause is a failure to sufficiently validate or sanitize dashboard definitions and associated metadata before processing.\nAn authenticated user holding the 'power' role possesses the capability to create and modify dashboards, allowing them to embed malicious Search Processing Language (SPL) strings directly into dashboard elements.\nBecause input sanitization and validation are missing within Splunk Web during the PDF export pipeline, the malicious SPL payload remains dormant until the rendering sequence is invoked.\nThe attack flow proceeds as follows: First, the attacker with the 'power' role authors or modifies a dashboard to include arbitrary, attacker-controlled SPL commands.\nSecond, the attacker deploys a phishing vector to trick an authenticated target user into initiating a request within their browser to export the compromised dashboard as a Portable Document Format (PDF) file.\nThird, upon receiving the request, Splunk Enterprise processes the dashboard elements for PDF generation and executes the injected SPL strings.\nCrucially, the execution of the injected SPL does not run within the restricted context of the authoring 'power' user; instead, it executes with the permissions and security context of the user initiating the PDF export.\nIf the victim user holds higher privileges or access to sensitive data sets, the injected SPL inherits those elevated privileges during execution.\nThe resulting payload behavior enables unauthorized data access, retrieval, or modification across any indices and data sources reachable by the victim user.\nAuthentication is required for both the attacker (holding the 'power' role) and the victim user (who performs the export).\nAffected versions include Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14."
}
CVE-2026-76328: Splunk Enterprise Stored SPL Injection (MEDIUM Severity, CVSS: 6.7) - Sceawere