PatchSiren cyber security CVE debrief
CVE-2026-76339 Splunk CVE debrief
A user without 'admin' or 'power' Splunk roles could inject arbitrary Search Processing Language (SPL) commands through the geostats command in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The injected SPL runs with the permissions of another authenticated user after that user initiates the attacker-controlled geostats search in Splunk Web. This could expose all relevant data available to the second user, including stored credentials, and modify lookup files that the second user has permission to change. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-26
Who should care
Splunk Enterprise administrators and users, especially those with limited roles, should be aware of this vulnerability and take necessary precautions to prevent exploitation. Affected operators should review their deployments for vulnerable versions and apply patches or updates. Platform administrators should verify that Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are updated. Vulnerability management teams should prioritize patching and monitor for suspicious geostats searches. Security teams should educate users on phishing risks and safe browsing practices to prevent exploitation.
Technical summary
The geostats command in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 does not sufficiently validate input, allowing a user without 'admin' or 'power' roles to inject arbitrary SPL commands. These commands run with the permissions of another authenticated user who initiates the attacker-controlled geostats search in Splunk Web. This could lead to exposure of sensitive data and modification of lookup files.
Defensive priority
Medium priority due to the required user interaction for exploitation
Recommended defensive actions
- Inventory and verify affected Splunk Enterprise versions
- Apply patches or updates to vulnerable versions
- Monitor for suspicious geostats searches
- Restrict user permissions to limit potential impact
- Educate users on phishing risks and safe browsing practices
Evidence notes
The CVE description provides details on the vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The vulnerability allows a user without 'admin' or 'power' roles to inject arbitrary SPL commands through the geostats command. The injected SPL runs with the permissions of another authenticated user after that user initiates the attacker-controlled geostats search in Splunk Web.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76339 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76339
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76339 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76339
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-0801
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.