PatchSiren cyber security CVE debrief
CVE-2026-76331 Splunk CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:17.423Z and has not been modified since then. This vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, allowing users without 'admin' or 'power' roles to inject SPL into saved-search dispatch requests. This could allow for unauthorized access to all relevant data and affect system integrity within Splunk Enterprise. The vulnerability is possible because Splunk Enterprise does not correctly validate caller-supplied time values before using them in saved-search dispatch. Organizations using Splunk Enterprise should prioritize patching vulnerable versions to prevent potential unauthorized access and system integrity issues. IT teams responsible for Splunk Enterprise deployments should review and implement the recommended actions to prevent exploitation of this vulnerability. Security teams should also monitor for potential attacks and verify the effectiveness of implemented mitigations.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Organizations using Splunk Enterprise, particularly those with users who do not hold 'admin' or 'power' roles, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing system logs for unauthorized access attempts, monitoring system integrity within Splunk Enterprise, and restricting access to saved-search dispatch requests for users without 'admin' or 'power' roles. Additionally, organizations should prioritize patching vulnerable versions to prevent potential unauthorized access and system integrity issues. IT teams responsible for Splunk Enterprise deployments should review and implement the recommended actions to prevent exploitation of this vulnerability. Security teams should also monitor for potential attacks and verify the effectiveness of implemented mitigations. Furthermore, organizations should ensure that their incident response plans are updated to address potential exploitation of this vulnerability, and that relevant personnel are trained on the necessary response procedures. Compliance teams should also review the vulnerability and associated mitigations to ensure that they align with regulatory requirements and industry standards. Lastly, users of Splunk Enterprise should be aware of the potential risks associated with this vulnerability and take steps to protect themselves, such as limiting access to sensitive data and monitoring system activity for suspicious behavior. The vulnerability's impact on an organization's security posture will depend on the specific use cases and configurations of Splunk Enterprise within their environment. Therefore, a thorough risk assessment should be conducted to determine the potential consequences of exploitation and the effectiveness of proposed mitigations. This assessment should consider factors such as the sensitivity of data stored in Splunk Enterprise, the potential for lateral movement within the network, and the availability of compensating controls. Based on this assessment, organizations can prioritize their mitigation efforts and allocate resources effectively to address the vulnerability. By taking a proactive and informed approach to addressing this vulnerability
Technical summary
The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, allowing users without 'admin' or 'power' roles to inject SPL into saved-search dispatch requests. This could allow for unauthorized access to all relevant data and affect system integrity within Splunk Enterprise. The vulnerability is possible because Splunk Enterprise does not correctly validate caller-supplied time values before using them in saved-search dispatch.
Defensive priority
Organizations using Splunk Enterprise should prioritize patching vulnerable versions to prevent potential unauthorized access and system integrity issues.
Recommended defensive actions
- Apply patches for Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14
- Restrict access to saved-search dispatch requests for users without 'admin' or 'power' roles
- Monitor system integrity within Splunk Enterprise for potential unauthorized access
- Review system logs for unauthorized access attempts
- Verify the effectiveness of implemented mitigations
- Update incident response plans to address potential exploitation of this vulnerability
- Ensure that relevant personnel are trained on the necessary response procedures
Evidence notes
The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, allowing users without 'admin' or 'power' roles to inject SPL into saved-search dispatch requests. Evidence is based on official CVE and NVD records. To verify, defenders should review system logs for unauthorized access attempts and monitor system integrity within Splunk Enterprise. Additionally, defenders should check for any unusual search queries or SPL injections.
Official resources
-
CVE-2026-76331 CVE record
CVE.org
-
CVE-2026-76331 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:17.423Z and has not been modified since then.