,

Vulnerability Watch No56

🛡️ Splunk flaw lets lower-privileged users write arbitrary dispatch metadata
Splunk Enterprise administrators should prioritize patching affected deployments and review role permissions. This is a HIGH severity issue, especially for environments where many users have search access.
CVE-2026-76344 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows users without admin or power roles to write dispatch metadata to arbitrary host locations. The vulnerability has a CVSS score of 7.7 and is rated HIGH. It can affect system integrity through insufficient validation of crafted search identifiers in a REST API endpoint.
🔗 Read more 🔗
Source: NVD

📊 Splunk Monitoring Console link flaw enables unauthorized searches
Patch Splunk installations and focus on user awareness because exploitation depends on opening crafted links. Review privileged Monitoring Console access where possible.
CVE-2026-76330 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows attackers to use crafted links to inject SPL into Monitoring Console searches. The vulnerability has a CVSS score of 7.1 and is rated HIGH. The attack requires phishing an authenticated user and can expose data accessible to that user.
🔗 Read more 🔗
Source: NVD

🔑 Splunk authentication weakness can enable forged admin sessions
Patch Splunk Enterprise quickly and protect distributed search private keys as sensitive credentials. Teams should investigate any unexpected use of administrative sessions after exposure.
CVE-2026-76338 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows attackers with access to a trusted distributed search private key to forge administrative session tokens. The vulnerability has a CVSS score of 8.1 and is rated HIGH. It can expose data, affect system integrity, and disrupt service availability.
🔗 Read more 🔗
Source: NVD

🧩 Splunk SPL2 API issue allows unauthorized module deletion
Organizations running SPL2 should patch affected Splunk instances promptly and review who can access module management functions. This issue is especially important for shared enterprise deployments.
CVE-2026-76336 affects Splunk Enterprise versions below 10.4.2 and 10.2.6 and allows users without admin or power roles to delete SPL2 modules across apps and users. The vulnerability has a CVSS score of 7.1 and is rated HIGH. It can remove exported datasets and functions, affecting system integrity and causing partial service disruption.
🔗 Read more 🔗
Source: NVD

💻 Splunk Web XML weakness enables operating system command execution
Patch immediately and review authenticated user privileges in Splunk Web. This is one of the more serious issues in the batch because it can lead to command execution.
CVE-2026-76335 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows authenticated users without the edit_manager_xml capability to write malicious Splunk Web Manager XML configurations. The vulnerability has a CVSS score of 8.8 and is rated HIGH. Opening the affected page can execute attacker-controlled operating-system commands as the Splunk user account.
🔗 Read more 🔗
Source: NVD

🌐 Splunk Dashboard Studio URL validation flaw exposes users to XSS
Patch affected Splunk systems and remind users to be cautious with unexpected workflow actions or links. Administrators should review power-role assignments.
CVE-2026-76333 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows power-role users to store crafted Dashboard Studio workflow actions. The vulnerability has a CVSS score of 7.1 and is rated HIGH. A phishing-style interaction can cause attacker-controlled JavaScript to run in another authenticated user’s browser.
🔗 Read more 🔗
Source: NVD

🔗 Splunk Analytics Workspace flaw allows injected searches
Apply Splunk updates and reinforce phishing awareness among users with Analytics Workspace access. Exploitation requires user interaction, but the impact can match the victim’s privileges.
CVE-2026-76332 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows attackers to trick authenticated users into opening crafted Analytics Workspace links. The vulnerability has a CVSS score of 7.1 and is rated HIGH. Injected SPL can run with the victim’s permissions and access available data or actions.
🔗 Read more 🔗
Source: NVD

🔍 Splunk saved-search validation bug enables SPL injection
Patch affected Splunk Enterprise systems quickly and audit saved-search activity. This issue should be treated as high priority because it can expose sensitive search results.
CVE-2026-76331 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows lower-privileged users to inject SPL into saved-search dispatch requests. The vulnerability has a CVSS score of 8.1 and is rated HIGH. It can allow unauthorized data access and affect system integrity.
🔗 Read more 🔗
Source: NVD

⚠️ Splunk UI tour XSS issue can run JavaScript in user browsers
Patch affected Splunk deployments and limit unnecessary power-role assignments. Teams should consider this urgent where many users access Splunk Web.
CVE-2026-76325 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows power-role users to store malicious ui-tour knowledge objects. The vulnerability has a CVSS score of 7.3 and is rated HIGH. It can execute arbitrary JavaScript in another authenticated user’s browser through a Cross-Site Scripting vulnerability.
🔗 Read more 🔗
Source: NVD

🧪 Splunk nearby-event search bug permits SPL injection
Apply the available Splunk fixes and review exposed Splunk Web functionality. Prioritize systems accessible to untrusted users.
CVE-2026-76321 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows unauthenticated attackers to inject SPL into nearby-event search requests. The vulnerability has a CVSS score of 7.3 and is rated HIGH. It can enable unauthorized search execution because of insufficient input escaping and authorization checks.
🔗 Read more 🔗
Source: NVD

🚨 Splunk Federated Search flaw enables remote code execution
Patch immediately because remote code execution issues deserve urgent handling in production Splunk environments. Review Federated Search permissions and capabilities after updating.
CVE-2026-76319 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows low-privileged users without the fsh_manage capability to perform Remote Code Execution through Federated Search bundle selection. The vulnerability has a CVSS score of 8.8 and is rated HIGH. It can affect data confidentiality, system integrity, and availability.
🔗 Read more 🔗
Source: NVD

📂 Splunk lookup path issue exposes readable files to users
Administrators should patch quickly and review lookup permissions and file access paths. Treat this as a high-risk data exposure issue in shared Splunk environments.
CVE-2026-76317 affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 and allows users without admin or power roles to move readable files into controlled lookups. The vulnerability has a CVSS score of 8.8 and is rated HIGH. It can expose data and affect system integrity and availability on the search head.
🔗 Read more 🔗
Source: NVD