PatchSiren cyber security CVE debrief
CVE-2026-76343 Splunk CVE debrief
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the 'admin' or 'power' Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint. This vulnerability allows for access to substantially all data stored by Data Orchestration, including jobs owned by other users and stored connection credentials. The issue arises because Data Orchestration builds database queries from user-controlled job filter values without using parameterized queries. To address this vulnerability, it is crucial for Splunk Enterprise administrators and users with access to the Data Orchestration jobs endpoint to review and update their systems, ensuring that role-based access control is properly implemented and that Data Orchestration job filter values are restricted.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Splunk Enterprise administrators and users with access to Data Orchestration jobs endpoint should review and update their systems to prevent unauthorized data access. This includes ensuring that role-based access control is properly implemented, and that Data Orchestration job filter values are restricted to prevent the execution of attacker-chosen SQL queries. Additionally, users with roles that could potentially be impacted by this vulnerability should be aware of the potential risks and take necessary precautions to protect their systems and data. It is also recommended to monitor Data Orchestration jobs endpoint for suspicious activity and consider implementing compensating controls, such as database query parameterization, to further mitigate the risk of this vulnerability. Users should also verify that their current Splunk Enterprise version is not vulnerable and plan for updates or mitigations through normal change control where exposure is confirmed. Furthermore, checking relevant monitoring, detection, and logs for exposed assets that need extra review is advisable. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are also important steps. Finally, confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up is essential for effective vulnerability management. Reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance is also crucial for an effective response to this vulnerability. This should be done while considering the broader context of the vulnerability, including its potential operational impact and the confidence in the source of the information. By taking these steps, organizations can effectively manage the risks associated with this vulnerability and protect their systems and data from potential attacks. The CVE record was published on 2026-08-19T22:17:19.023Z and has not been modified since then, emphasizing the need for prompt action based on the information available at the time of publication. The vulnerability's MEDIUM severity rating underscores the importance of addressing,
Technical summary
The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user without 'admin' or 'power' roles could execute attacker-chosen SQL queries through the Data Orchestration jobs endpoint, allowing access to substantially all data stored by Data Orchestration. The issue arises from Data Orchestration building database queries from user-controlled job filter values without using parameterized queries.
Defensive priority
Medium-priority defensive actions are required to address this vulnerability, as it allows for unauthorized data access.
Recommended defensive actions
- Review and update Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14, or later
- Implement role-based access control and restrict Data Orchestration job filter values
- Monitor Data Orchestration jobs endpoint for suspicious activity
- Consider compensating controls, such as database query parameterization
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user without 'admin' or 'power' roles could execute attacker-chosen SQL queries through the Data Orchestration jobs endpoint, allowing access to substantially all data stored by Data Orchestration. The issue arises from Data Orchestration building database queries from user-controlled job filter values without using parameterized queries.
Official resources
-
CVE-2026-76343 CVE record
CVE.org
-
CVE-2026-76343 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:19.023Z and has not been modified since then.