← All Advisories

Splunk Enterprise Evaluates Web Manager Configuration XML Without Sufficient Input Restrictions, Enabling Low-Privilege Users to Execute Arbitrary Code

Last refreshed2026-09-29

Status: UPDATED  |  Advisory ID: CVE-2026-76314

Key Details

CVECVE-2026-76314
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-08-27
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSplunk splunk
Classified asCWE-94 (Improper Control of Generation of Code ('Code Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Splunksplunk
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect system integrity and availability. The vulnerability is possible because Splunk Web evaluates manager Extensible Markup Language expressions without sufficient input restrictions, and the associated configuration route does not require the capability expected for manager configuration changes. For more information see About configuration files (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.4/administer-splunk-enterprise-with-configuration-files/about-configuration-files) in the Splunk documentation. (NVD)

What to Do

Monitor Splunk's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-76314
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-76314
Vendor advisoryhttps://advisory.splunk.com/advisories/SVD-2026-0801