CVE-2026-76314

8.8

Splunk · Enterprise

Splunk Enterprise contains a code injection vulnerability where improper input neutralization allows attackers to execute arbitrary code.

Executive summary

A high-severity code injection vulnerability in Splunk Enterprise allows authenticated attackers to execute arbitrary code by manipulating system inputs.

Vulnerability

This is a code injection vulnerability (CWE-94) where the application fails to properly neutralize user-influenced input before using it in a code segment. This vulnerability allows an authenticated remote attacker to alter the behavior of the software.

Business impact

The ability to inject and execute arbitrary code carries the highest risk of system compromise. A CVSS score of 8.8 highlights the potential for full system control, which could result in data theft, persistent malware installation, or total platform failure.

Remediation

Immediate Action: Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, 9.4.14, or higher immediately.

Proactive Monitoring: Monitor system logs for suspicious process execution, unexpected child processes spawned by the Splunk service, or attempts to execute system-level commands via the web interface.

Compensating Controls: Employ a Web Application Firewall (WAF) with updated rulesets to inspect incoming requests for signs of code injection or command execution payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Immediate patching is required to neutralize this code injection risk. Organizations should prioritize updating their Splunk Enterprise instances to the latest versions to prevent potential remote code execution by authenticated attackers.

More Splunk CVEs