Splunk Enterprise Multiple SPL Injection Vulnerabilities (CVE-2026-76254, CVE-2026-76255, CVE-2026-76322, CVE-2026-76323)

Release Date: 24th August 2026 (Added 1 September 2026)

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate Splunk Enterprise. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-76254, CVE-2026-76255, CVE-2026-76322 and CVE-2026-76323 are Search Processing Language (SPL) injection vulnerabilities in Splunk Enterprise. Each allows SPL safeguards designed to stop risky, attacker-controlled searches from being bypassed through a different Splunk feature: the Dataset Explorer, the Data Model Editor, Dashboard Studio dashboards, and Job Details dashboard links respectively.

The most severe, CVE-2026-76254 (CVSS 7.5), lets an unauthenticated user manipulate dataset names to dispatch arbitrary SPL pipelines without the normal safeguards, potentially exposing sensitive indexed data. The remaining three require an authenticated but low-privileged user, and in most cases a social-engineering step such as getting another user to open a crafted dashboard or link, to run attacker-controlled SPL in the context of a more privileged user.

Reference

  1. https://advisory.splunk.com/advisories/SVD-2026-0801
  2. https://www.cve.org/CVERecord?id=CVE-2026-76254
  3. https://www.cve.org/CVERecord?id=CVE-2026-76255
  4. https://www.cve.org/CVERecord?id=CVE-2026-76322
  5. https://www.cve.org/CVERecord?id=CVE-2026-76323