cbcvebase.
CVE-2026-76320
published 2026-08-19

CVE-2026-76320: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authenticated user to run arbitrary Search…

PriorityP337medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.21%
11.0th percentile
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authenticated user to run arbitrary Search Processing Language (SPL) searches on their behalf through the Event Type Builder. This could expose all relevant data and stored credentials. The vulnerability is possible when the Event Type Builder accepts cross-site request input and retains SPL-affecting values while building sample event searches. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Automatically find and build event types (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/9.0/event-types/automatically-find-and-build-event-types) in the Splunk documentation.

Affected

8 ranges
VendorProductVersion rangeFixed in
splunksplunk>= 10.0.0 < 10.0.910.0.9
splunksplunk>= 10.2.0 < 10.2.610.2.6
splunksplunk>= 10.4.0 < 10.4.210.4.2
splunksplunk>= 9.4.0 < 9.4.149.4.14
splunksplunk_enterprise>= 10.0 < 10.0.910.0.9
splunksplunk_enterprise>= 10.2 < 10.2.610.2.6
splunksplunk_enterprise>= 10.4 < 10.4.210.4.2
splunksplunk_enterprise>= 9.4 < 9.4.149.4.14
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.