CVE-2026-76330
published 2026-08-19CVE-2026-76330: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link…
PriorityP339high7.1CVSS 3.1
AVNACHPRNUIRSUCHIHAL
EPSS
0.25%
16.2th percentile
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions available to that user. The vulnerability is possible because Monitoring Console does not sufficiently validate data used to build forwarder dashboard searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| splunk | splunk | >= 10.0.0 < 10.0.9 | 10.0.9 |
| splunk | splunk | >= 10.2.0 < 10.2.6 | 10.2.6 |
| splunk | splunk | >= 10.4.0 < 10.4.2 | 10.4.2 |
| splunk | splunk | >= 9.4.0 < 9.4.14 | 9.4.14 |
| splunk | splunk_enterprise | >= 10.0 < 10.0.9 | 10.0.9 |
| splunk | splunk_enterprise | >= 10.2 < 10.2.6 | 10.2.6 |
| splunk | splunk_enterprise | >= 10.4 < 10.4.2 | 10.4.2 |
| splunk | splunk_enterprise | >= 9.4 < 9.4.14 | 9.4.14 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console.
ghsa_unreviewed·2026-08-20
CVE-2026-76330 [HIGH] CWE-20 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console.
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions available to that user. The vulnerability is possible because Monitoring Console does not sufficiently validate data used to build forwarder dashboard searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will.
VulDB
Splunk Enterprise up to 9.4.13/10.0.8/10.2.5/10.4.1 Monitoring Console injection
vuldb·2026-08-20·CVSS 7.1
CVE-2026-76330 [HIGH] Splunk Enterprise up to 9.4.13/10.0.8/10.2.5/10.4.1 Monitoring Console injection
A vulnerability has been found in Splunk Enterprise up to 9.4.13/10.0.8/10.2.5/10.4.1 and classified as very critical. This impacts an unknown function of the component Monitoring Console. Performing a manipulation results in injection.
This vulnerability is identified as CVE-2026-76330. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published