Sceawere

Vulnerability Detail

CVE-2026-76335UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Splunk Enterprise Remote Code Execution

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
5h ago
Vendor
Splunk
Product
Splunk Enterprise
Attack Type
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. When the same user opens the affected Splunk Web Manager page, Splunk Enterprise runs attacker-controlled operating-system commands as the user account running Splunk Enterprise. The vulnerability is possible because Splunk Web does not require the edit_manager_xml capability before accepting Splunk Web Manager XML configuration changes.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-19T22:17:17.973Z",
  "pubdate": "2026-08-19T22:17:17.973Z",
  "executiveSummary": "Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 contain an improper authorization vulnerability in Splunk Web.\nThe vulnerability allows an authenticated user lacking the edit_manager_xml capability to write malicious Splunk Web Manager Extensible Markup Language (XML) configurations.\nWhen the user subsequently accesses the affected Splunk Web Manager page, the application executes attacker-controlled operating-system commands directly within the context of the user account running Splunk Enterprise.\nThis introduces a critical risk of remote code execution and complete system compromise under the privileges of the underlying service account.\nExploitation requires authenticated access to the application and the ability to interact with Splunk Web Manager configuration interfaces.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient access control enforcement within the Splunk Web component.\nSpecifically, the application fails to validate whether an authenticated user holds the required edit_manager_xml capability before accepting configuration changes submitted via Splunk Web Manager XML.\nBecause the authorization check is missing, a standard authenticated user who is not assigned a privileged administrative role can successfully submit and persist modified XML configurations.\nThe attack flow proceeds in two primary phases: configuration injection and execution.\nIn the first phase, the low-privileged attacker crafts and submits a malicious Splunk Web Manager XML configuration payload containing arbitrary operating-system commands.\nIn the second phase, when the attacker opens the affected Splunk Web Manager page, the Splunk Enterprise backend parses the malicious XML configuration.\nDuring this parsing and rendering lifecycle, the embedded operating-system commands are executed by the host operating system under the security context of the user account running Splunk Enterprise.\nThe affected component is the Splunk Web Manager interface within Splunk Enterprise.\nVulnerable product versions include all releases below 10.4.2, 10.2.6, 10.0.9, and 9.4.14.\nThe vulnerability requires authenticated access to the application, but does not require administrative privileges or the edit_manager_xml capability.\nSuccessful exploitation results in arbitrary command execution on the host operating system, leading to potential post-exploitation risks such as privilege escalation, data exfiltration, or complete infrastructure takeover depending on the privileges assigned to the Splunk service account."
}
CVE-2026-76335: Splunk Enterprise Remote Code Execution (HIGH Severity, CVSS: 8.8) - Sceawere