CVE-2026-76335
8.8Splunk · Enterprise
Splunk Enterprise is susceptible to code injection due to improper neutralization of externally influenced input, allowing authenticated users to modify intended code execution.
Executive summary
A critical code injection vulnerability in Splunk Enterprise enables authenticated attackers to influence code execution, threatening the integrity of the entire platform.
Vulnerability
This is a code injection vulnerability (CWE-94) where the software constructs code segments using unvalidated input. The vulnerability is accessible to authenticated users with low privileges.
Business impact
The ability to inject arbitrary code into the application environment carries severe implications, including full system compromise, remote code execution, and total loss of data confidentiality. The CVSS score of 8.8 underscores the high level of danger this vulnerability poses to organizational security posture.
Remediation
Immediate Action: Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14, or higher.
Proactive Monitoring: Monitor system logs for unexpected process execution or abnormal behavior originating from the Splunk service account.
Compensating Controls: Ensure the principle of least privilege is applied to all service accounts and utilize host-based intrusion detection systems to monitor for unauthorized modifications to configuration or script files.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the potential for complete system compromise, this issue must be addressed with high urgency. Organizations are strongly advised to schedule maintenance windows to update their Splunk Enterprise deployments to the recommended fixed versions immediately.