What is CVE-2026-76350?
This vulnerability allows a user with the schedule_search capability in certain versions of Splunk Enterprise to configure PDF attachments in email alerts, which can lead to arbitrary Search Processing Language (SPL) command execution. Affected users should apply the security patch and review schedule_search role assignments.
Azərbaycanca: Bu zəiflik Splunk Enterprise-in müəyyən versiyalarında schedule_search icazəsi olan istifadəçiyə e-poçt bildirişlərinə PDF əlavəsi konfiqurasiya etməyə imkan verir. Bu əməliyyat nəticəsində ixtiyari Search Processing Language (SPL) kodunun icrası mümkündür. İstifadəçilərə təhlükəsizlik yaması tətbiq etmək və schedule_search icazələrini nəzərdən keçirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Splunk
FAQ2
What specific capability must an attacker have to exploit CVE-2026-76350?
To exploit this vulnerability, an attacker must have the schedule_search capability in Splunk Enterprise.
What can successful exploitation of CVE-2026-76350 lead to?
Successful exploitation can lead to arbitrary Search Processing Language (SPL) command execution by configuring PDF attachments in email alerts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.