CVE-2026-76309
Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the "admin" or "power" Splunk roles could inject Structured Query Language (SQL) through the Representational State Transfer (REST) API, causing Splunk Enterprise to evaluate attacker-controlled text as part of a database query. The SQL injection is possible because the REST API incorporates user-supplied filter values into database queries without proper neutralization.
| CWE | CWE-89 |
| Vendor | splunk |
| Product | splunk enterprise |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for splunk splunk enterprise
Be the first to know when new medium vulnerabilities affecting splunk splunk enterprise are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Splunk / Splunk Enterprise
10.4 < 10.4.2 10.2 < 10.2.6 10.0 < 10.0.9 9.4 < 9.4.14
References
Credits
๐ Gabriel Nitu, Splunk