SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76350

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable due to a flaw that allows users with the schedule_search capability to execute arbitrary Search Processing Language (SPL) commands with system-level privileges through email alert actions that include PDF attachments. This could lead to unauthorized data exposure, compromising system integrity and availability on the search head. Organizations using affected versions, particularly those with users assigned the schedule_search role, should prioritize applying the necessary updates to mitigate this high-severity vulnerability.

CVE
CVE-2026-76350
Severity
HIGH
CVSS
8.8
EPSS
0.28%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure Portable Document Format (PDF) attachments in the email alert action workflow. When the email alert action runs, it could execute arbitrary Search Processing Language (SPL) commands with system-level privileges, expose all relevant data, and affect system integrity and availability on the search head. The vulnerability is possible because the search scheduler passes a system-level authentication context rather than the action owner context to the email alert action when it renders PDF attachments. For more information see alert_actions.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/alert_actions.conf) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)