PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76341 Splunk CVE debrief

The CVE-2026-76341 vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store attacker-controlled Search Processing Language (SPL) in a Table Editor dataset and share it. A user with the 'admin' Splunk role triggers the SPL when opening the dataset, which runs with the permissions of the second user, potentially exposing all relevant data and modifying limited data. This vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the 'power' Splunk role should not be able to exploit the vulnerability at will. To address this, Splunk Enterprise administrators and users with 'power' or 'admin' roles should be aware of this vulnerability and take necessary actions to prevent potential data exposure and modification.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-26
Advisory published
2026-08-19
Advisory updated
2026-08-26

Who should care

Splunk Enterprise administrators and users with 'power' or 'admin' roles should be aware of this vulnerability and take necessary actions to prevent potential data exposure and modification. They should prioritize patching to prevent potential data exposure and modification. Additionally, they should restrict 'power' and 'admin' Splunk roles to minimize exposure, monitor Table Editor dataset sharing and SPL execution, and implement compensating controls to detect and prevent data exposure.

Technical summary

The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store attacker-controlled Search Processing Language (SPL) in a Table Editor dataset and share it. A user with the 'admin' Splunk role triggers the SPL when opening the dataset, which runs with the permissions of the second user, potentially exposing all relevant data and modifying limited data. The Table Editor does not apply SPL safeguards for risky commands when preparing the dataset initial data.

Defensive priority

Splunk Enterprise users with 'power' or 'admin' roles should prioritize patching to prevent potential data exposure and modification.

Recommended defensive actions

  • Patch Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, or 9.4.14.
  • Restrict 'power' and 'admin' Splunk roles to minimize exposure.
  • Monitor Table Editor dataset sharing and SPL execution.
  • Implement compensating controls to detect and prevent data exposure.
  • Review and update access controls for Table Editor datasets.
  • Conduct regular security audits to identify potential vulnerabilities.
  • Establish incident response plans in case of potential data breaches.

Evidence notes

The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store attacker-controlled Search Processing Language (SPL) in a Table Editor dataset and share it. A user with the 'admin' Splunk role triggers the SPL when opening the dataset, which runs with the permissions of the second user, potentially exposing all relevant data and modifying limited data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76341 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76341

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76341 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76341

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.