CVE-2026-76254: Splunk Enterprise: SPL injection via Dataset Explorer
HIGHSplunk Enterprise's Dataset Explorer builds Search Processing Language (SPL) queries from dataset names without validating or escaping them and without applying SPL safeguards for risky commands, letting a crafted link force a logged-in user to unknowingly run arbitrary SPL with their own privileges. The attack requires no authentication to launch but does require phishing a victim into clicking a link, which caps the CVSS at 7.5 (AC:H, UI:R) rather than a wormable critical — there's no EPSS score published yet, it's not in CISA KEV, and no public exploit or Nuclei template exists, so this reads as a patch-on-schedule issue rather than a fire drill. The real exposure is blast radius: because SPL execution inherits the victim's role, a phished admin or power user hands the attacker read access to indexed data and the ability to run destructive risky commands, hitting confidentiality, integrity, and availability simultaneously. Patch to Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, 9.4.14, or 9.3.14 (whichever branch you run), and in the interim tighten SPL safeguards for risky commands and audit who has Dataset Explorer access. Worth flagging: this is a general Splunk platform CVE, not an AI/ML-specific vulnerability — it landed in this feed's `ml_data` category because Splunk is frequently used to index and query datasets, including telemetry from AI/ML pipelines, not because the flaw itself targets an AI system.
What is the risk?
High severity (CVSS 7.5) but not critical-urgent: the attack chain requires user interaction (a victim clicking a phishing link) and no authentication from the attacker, which lowers real-world exploitation likelihood versus a directly remotely-exploitable flaw. No EPSS score, no CISA KEV listing, no known public exploit code or Nuclei template — nothing indicates active or imminent exploitation. The impact ceiling is high, though: a successful phish yields full confidentiality/integrity/availability compromise scoped to the victim's Splunk privileges, which for an admin account could mean broad access to indexed data and destructive SPL command execution. Treat this as high-priority patch-cycle work, not an emergency out-of-band change.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Splunk Enterprise | — | — | No patch |
Do you use Splunk Enterprise? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Patch to the fixed Splunk Enterprise version for your branch: 10.4.2, 10.2.6, 10.0.9, 9.4.14, or 9.3.14. Until patched, review and enforce SPL safeguards for risky commands per Splunk's hardening guidance, restrict Dataset Explorer access to only users who need it, and train privileged Splunk users to treat unsolicited Dataset Explorer links with the same suspicion as any credential-phishing link. Monitor Splunk internal audit logs for SPL searches dispatched from Dataset Explorer that reference unusual or malformed dataset names, and for risky-command executions (e.g.,
delete,collect,outputlookup) triggered outside normal user workflow patterns.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-76254?
Splunk Enterprise's Dataset Explorer builds Search Processing Language (SPL) queries from dataset names without validating or escaping them and without applying SPL safeguards for risky commands, letting a crafted link force a logged-in user to unknowingly run arbitrary SPL with their own privileges. The attack requires no authentication to launch but does require phishing a victim into clicking a link, which caps the CVSS at 7.5 (AC:H, UI:R) rather than a wormable critical — there's no EPSS score published yet, it's not in CISA KEV, and no public exploit or Nuclei template exists, so this reads as a patch-on-schedule issue rather than a fire drill. The real exposure is blast radius: because SPL execution inherits the victim's role, a phished admin or power user hands the attacker read access to indexed data and the ability to run destructive risky commands, hitting confidentiality, integrity, and availability simultaneously. Patch to Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, 9.4.14, or 9.3.14 (whichever branch you run), and in the interim tighten SPL safeguards for risky commands and audit who has Dataset Explorer access. Worth flagging: this is a general Splunk platform CVE, not an AI/ML-specific vulnerability — it landed in this feed's `ml_data` category because Splunk is frequently used to index and query datasets, including telemetry from AI/ML pipelines, not because the flaw itself targets an AI system.
Is CVE-2026-76254 actively exploited?
No confirmed active exploitation of CVE-2026-76254 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-76254?
Patch to the fixed Splunk Enterprise version for your branch: 10.4.2, 10.2.6, 10.0.9, 9.4.14, or 9.3.14. Until patched, review and enforce SPL safeguards for risky commands per Splunk's hardening guidance, restrict Dataset Explorer access to only users who need it, and train privileged Splunk users to treat unsolicited Dataset Explorer links with the same suspicion as any credential-phishing link. Monitor Splunk internal audit logs for SPL searches dispatched from Dataset Explorer that reference unusual or malformed dataset names, and for risky-command executions (e.g., `delete`, `collect`, `outputlookup`) triggered outside normal user workflow patterns.
What systems are affected by CVE-2026-76254?
This vulnerability affects the following AI/ML architecture patterns: SIEM-integrated data pipelines (indirect — where AI/ML telemetry or training-data logs are indexed in Splunk), Dataset management interfaces.
What is the CVSS score for CVE-2026-76254?
CVE-2026-76254 has a CVSS v3.1 base score of 7.5 (HIGH). The EPSS exploitation probability is 0.42%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0011.003 Malicious Link AML.T0052 Phishing Compliance Controls Affected
What are the technical details?
Original Advisory
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) pipelines from Dataset Explorer with the same privileges as that user, which can allow for access to all relevant data and system integrity available to that user and affect system availability. The vulnerability is possible because Dataset Explorer does not validate or escape dataset names before building SPL searches and does not apply SPL safeguards for risky commands to those searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Explore a dataset (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/10.4/manage-and-explore-datasets/explore-a-dataset) and SPL safeguards for risky commands (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/best-practices-for-splunk-platform-security/spl-safeguards-for-risky-commands) in the Splunk documentation.
Exploitation Scenario
An attacker with no Splunk credentials crafts a Dataset Explorer URL embedding a malicious dataset name containing unescaped SPL syntax, then sends it to a privileged Splunk user via email or chat disguised as a legitimate dashboard link. When the victim clicks it while authenticated, Splunk builds and dispatches the attacker-controlled SPL pipeline using the victim's session and role, since Dataset Explorer doesn't apply risky-command safeguards to these generated searches. If the victim holds broad index access, the attacker-controlled SPL can read sensitive indexed data (including any ingested AI pipeline logs or datasets) or run destructive commands, all without ever authenticating to Splunk directly.
Weaknesses (CWE)
CWE-943 — Improper Neutralization of Special Elements in Data Query Logic: The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H References
Timeline
Related Vulnerabilities
CVE-2023-3765 10.0 MLflow: path traversal allows arbitrary file read
Same attack type: Data Extraction CVE-2025-5120 10.0 smolagents: sandbox escape enables unauthenticated RCE
Same attack type: Code Execution CVE-2025-2828 10.0 LangChain RequestsToolkit: SSRF exposes cloud metadata
Same attack type: Data Extraction CVE-2025-53767 10.0 Azure OpenAI: SSRF EoP, no auth required (CVSS 10)
Same attack type: Data Extraction CVE-2025-59528 10.0 Flowise: Unauthenticated RCE via MCP config injection
Same attack type: Code Execution