CVE-2026-76255: In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power"
Summary
In Splunk Enterprise versions before 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a low-privilege user can trick another user into running harmful commands through the Data Model Editor by sending them a malicious link (phishing attack). These commands could access data and damage the system because Splunk Web doesn't properly filter risky SPL commands (Search Processing Language, the query language Splunk uses) in this specific tool.
Solution / Mitigation
Update Splunk Enterprise to version 10.4.1, 10.2.6, 10.0.8, or 9.4.13 or later, depending on which branch you are running.
Vulnerability Details
6.4(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
network
high
low
required
August 19, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76255
First tracked: August 19, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 95%