SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76320

MEDIUM · CVSS 5.9 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to an issue where an unauthenticated user can exploit the Event Type Builder to execute arbitrary Search Processing Language (SPL) searches on behalf of an authenticated user, potentially exposing sensitive data and stored credentials. This vulnerability requires social engineering tactics to trick the authenticated user into initiating a request, making it crucial for organizations using affected Splunk versions to prioritize patching to mitigate the risk of data exposure. Security teams should focus on user training and awareness to prevent phishing attempts that could exploit this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76320
Severity
MEDIUM
CVSS
5.9
EPSS
0.21%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authenticated user to run arbitrary Search Processing Language (SPL) searches on their behalf through the Event Type Builder. This could expose all relevant data and stored credentials. The vulnerability is possible when the Event Type Builder accepts cross-site request input and retains SPL-affecting values while building sample event searches. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Automatically find and build event types (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/9.0/event-types/automatically-find-and-build-event-types) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)