CVE-2026-76309
Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise
Severity
Medium 4.3
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.7th percentile
Discovered by
Not disclosed
Published
Aug 19, 2026
Assigned by cisco
Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the "admin" or "power" Splunk roles could inject Structured Query Language (SQL) through the Representational State Transfer (REST) API, causing Splunk Enterprise to evaluate attacker-controlled text as part of a database query. The SQL injection is possible because the REST API incorporates user-supplied filter values into database queries without proper neutralization.
Weakness: CWE-89
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Enterprise | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Splunk · Splunk Enterprise
Credit
Gabriel Nitu, Splunk
Vendor remediation
Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.