SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76343

MEDIUM · CVSS 6.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

In Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, non-admin users can exploit a vulnerability in the Data Orchestration jobs endpoint to execute arbitrary SQL queries, potentially accessing sensitive data, including jobs and credentials belonging to other users. This flaw arises from the lack of parameterized queries, allowing unauthorized data access. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-76343
Severity
MEDIUM
CVSS
6.5
EPSS
0.28%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint, allowing for access to substantially all data stored by Data Orchestration, including jobs owned by other users and stored connection credentials. The vulnerability is possible because Data Orchestration builds a database query from user-controlled job filter values without using parameterized queries. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)