SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76254

HIGH · CVSS 7.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

In Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user can exploit a vulnerability in Dataset Explorer to dispatch arbitrary Search Processing Language (SPL) pipelines, potentially gaining access to sensitive data and compromising system integrity. This attack requires social engineering to trick a legitimate user into executing a malicious link, making it critical for organizations using affected versions to prioritize patching to mitigate risks associated with unauthorized data access and system availability. Security teams should focus on updating their Splunk installations and educating users about phishing tactics to reduce the likelihood of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76254
Severity
HIGH
CVSS
7.5
EPSS
0.31%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) pipelines from Dataset Explorer with the same privileges as that user, which can allow for access to all relevant data and system integrity available to that user and affect system availability. The vulnerability is possible because Dataset Explorer does not validate or escape dataset names before building SPL searches and does not apply SPL safeguards for risky commands to those searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Explore a dataset (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/10.4/manage-and-explore-datasets/explore-a-dataset) and SPL safeguards for risky commands (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/best-practices-for-splunk-platform-security/spl-safeguards-for-risky-commands) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)