What is CVE-2026-76349?
This vulnerability affects Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14. An unauthenticated user can trick an authenticated user into executing arbitrary SPL commands with the authenticated user's permissions via a crafted web link. It is recommended to update Splunk Enterprise to the specified versions or higher to mitigate the risk.
Azərbaycanca: Bu boşluq Splunk Enterprise-in 10.2.6, 10.0.9 və 9.4.14-dən aşağı versiyalarına təsir edir. Təsdiqlənməmiş istifadəçi, xüsusi hazırlanmış veb keçid vasitəsilə autentifikasiyalı istifadəçinin icazələri ilə özbaşına SPL (Search Processing Language) əmrləri işlədə bilər. Təsirə məruz qalmamaq üçün Splunk Enterprise-i göstərilən versiyalara və ya daha yuxarıya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of Splunk Enterprise are affected by CVE-2026-76349?
CVE-2026-76349 affects Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14.
What action is recommended to mitigate the risk associated with CVE-2026-76349?
To mitigate the risk, it is recommended to update Splunk Enterprise to versions 10.2.6, 10.0.9, 9.4.14 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.