What is CVE-2026-76339?
CVE-2026-76339 allows SPL injection in Splunk Enterprise via the geostats command in versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user without 'admin' or 'power' roles can inject arbitrary SPL commands that execute with the permissions of another authenticated user. Immediate patching or access control review is strongly recommended.
Azərbaycanca: CVE-2026-76339 Splunk Enterprise-in müəyyən versiyalarında "geostats" əmri vasitəsilə SPL inyeksiyasına imkan verir. Bu boşluq "admin" və ya "power" roluna malik olmayan istifadəçilərə başqa autentifikasiya olunmuş istifadəçinin icazələri ilə ixtiyari SPL əmrləri icra etməyə şərait yaradır. Təsirə məruz qalan versiyaları dərhal yamalı və ya giriş nəzarətlərini nəzərdən keçirməlisiniz.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Splunk
FAQ2
Which Splunk users can exploit CVE-2026-76339?
Authenticated users who do not have the 'admin' or 'power' role.
What command is exploited in CVE-2026-76339?
The 'geostats' command is used for SPL injection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.