CVE-2026-76335: Splunk

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. When the same user opens the affected Splunk Web Manager page, Splunk Enterprise runs attacker-controlled operating-system commands as the user account running Splunk Enterprise. The vulnerability is possible because Splunk Web does not require the edit_manager_xml capability before accepting Splunk Web Manager XML configuration changes.

Affected products

  • Splunk Splunk: from 9.4.0, before 9.4.14 (fixed in 9.4.14); from 10.0.0, before 10.0.9 (fixed in 10.0.9); from 10.2.0, before 10.2.6 (fixed in 10.2.6); from 10.4.0, before 10.4.2 (fixed in 10.4.2)

Published 2026-08-19. Last modified 2026-08-27.