PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76343 Splunk CVE debrief

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the 'admin' or 'power' Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint. This vulnerability allows for access to substantially all data stored by Data Orchestration, including jobs owned by other users and stored connection credentials. The issue arises because Data Orchestration builds database queries from user-controlled job filter values without using parameterized queries. To address this vulnerability, it is crucial for Splunk Enterprise administrators and users with access to the Data Orchestration jobs endpoint to review and update their systems, ensuring that role-based access control is properly implemented and that Data Orchestration job filter values are restricted.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-21
Advisory published
2026-08-19
Advisory updated
2026-08-21

Who should care

Splunk Enterprise administrators and users with access to Data Orchestration jobs endpoint should review and update their systems to prevent unauthorized data access. This includes ensuring that role-based access control is properly implemented, and that Data Orchestration job filter values are restricted to prevent the execution of attacker-chosen SQL queries. Additionally, users with roles that could potentially be impacted by this vulnerability should be aware of the potential risks and take necessary precautions to protect their systems and data. It is also recommended to monitor Data Orchestration jobs endpoint for suspicious activity and consider implementing compensating controls, such as database query parameterization, to further mitigate the risk of this vulnerability. Users should also verify that their current Splunk Enterprise version is not vulnerable and plan for updates or mitigations through normal change control where exposure is confirmed. Furthermore, checking relevant monitoring, detection, and logs for exposed assets that need extra review is advisable. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are also important steps. Finally, confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up is essential for effective vulnerability management. Reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance is also crucial for an effective response to this vulnerability. This should be done while considering the broader context of the vulnerability, including its potential operational impact and the confidence in the source of the information. By taking these steps, organizations can effectively manage the risks associated with this vulnerability and protect their systems and data from potential attacks. The CVE record was published on 2026-08-19T22:17:19.023Z and has not been modified since then, emphasizing the need for prompt action based on the information available at the time of publication. The vulnerability's MEDIUM severity rating underscores the importance of addressing,

Technical summary

The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user without 'admin' or 'power' roles could execute attacker-chosen SQL queries through the Data Orchestration jobs endpoint, allowing access to substantially all data stored by Data Orchestration. The issue arises from Data Orchestration building database queries from user-controlled job filter values without using parameterized queries.

Defensive priority

Medium-priority defensive actions are required to address this vulnerability, as it allows for unauthorized data access.

Recommended defensive actions

  • Review and update Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14, or later
  • Implement role-based access control and restrict Data Orchestration job filter values
  • Monitor Data Orchestration jobs endpoint for suspicious activity
  • Consider compensating controls, such as database query parameterization
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user without 'admin' or 'power' roles could execute attacker-chosen SQL queries through the Data Orchestration jobs endpoint, allowing access to substantially all data stored by Data Orchestration. The issue arises from Data Orchestration building database queries from user-controlled job filter values without using parameterized queries.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:19.023Z and has not been modified since then.