Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-76350

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure Portable Document Format (PDF) attachments in the email alert action workflow. When the email alert action runs, it could execute arbitrary Search Processing Language (SPL) commands with system-level privileges, expose all relevant data, and affect system integrity and availability on the search head. The vulnerability is possible because the search scheduler passes a system-level authentication context rather than the action owner context to the email alert action when it renders PDF attachments. For more information see alert_actions.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/alert_actions.conf) in the Splunk documentation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-76350
  • Splunk » Splunk » Version: 10.0.0
    cpe:2.3:a:splunk:splunk:10.0.0
  • Splunk » Splunk » Version: 10.0.1
    cpe:2.3:a:splunk:splunk:10.0.1
  • Splunk » Splunk » Version: 10.0.2
    cpe:2.3:a:splunk:splunk:10.0.2
  • Splunk » Splunk » Version: 10.0.3
    cpe:2.3:a:splunk:splunk:10.0.3
  • Splunk » Splunk » Version: 10.0.4
    cpe:2.3:a:splunk:splunk:10.0.4
  • Splunk » Splunk » Version: 10.0.5
    cpe:2.3:a:splunk:splunk:10.0.5
  • Splunk » Splunk » Version: 10.0.7
    cpe:2.3:a:splunk:splunk:10.0.7
  • Splunk » Splunk » Version: 10.0.8
    cpe:2.3:a:splunk:splunk:10.0.8
  • Splunk » Splunk » Version: 10.2.0
    cpe:2.3:a:splunk:splunk:10.2.0
  • Splunk » Splunk » Version: 10.2.1
    cpe:2.3:a:splunk:splunk:10.2.1
  • Splunk » Splunk » Version: 10.2.2
    cpe:2.3:a:splunk:splunk:10.2.2
  • Splunk » Splunk » Version: 10.2.4
    cpe:2.3:a:splunk:splunk:10.2.4
  • Splunk » Splunk » Version: 10.2.5
    cpe:2.3:a:splunk:splunk:10.2.5
  • Splunk » Splunk » Version: 10.4.0
    cpe:2.3:a:splunk:splunk:10.4.0
  • Splunk » Splunk » Version: 10.4.1
    cpe:2.3:a:splunk:splunk:10.4.1
  • Splunk » Splunk » Version: 9.4.0
    cpe:2.3:a:splunk:splunk:9.4.0
  • Splunk » Splunk » Version: 9.4.1
    cpe:2.3:a:splunk:splunk:9.4.1
  • Splunk » Splunk » Version: 9.4.10
    cpe:2.3:a:splunk:splunk:9.4.10
  • Splunk » Splunk » Version: 9.4.11
    cpe:2.3:a:splunk:splunk:9.4.11
  • Splunk » Splunk » Version: 9.4.12
    cpe:2.3:a:splunk:splunk:9.4.12
  • Splunk » Splunk » Version: 9.4.13
    cpe:2.3:a:splunk:splunk:9.4.13
  • Splunk » Splunk » Version: 9.4.2
    cpe:2.3:a:splunk:splunk:9.4.2
  • Splunk » Splunk » Version: 9.4.3
    cpe:2.3:a:splunk:splunk:9.4.3
  • Splunk » Splunk » Version: 9.4.4
    cpe:2.3:a:splunk:splunk:9.4.4
  • Splunk » Splunk » Version: 9.4.5
    cpe:2.3:a:splunk:splunk:9.4.5
  • Splunk » Splunk » Version: 9.4.6
    cpe:2.3:a:splunk:splunk:9.4.6
  • Splunk » Splunk » Version: 9.4.7
    cpe:2.3:a:splunk:splunk:9.4.7
  • Splunk » Splunk » Version: 9.4.8
    cpe:2.3:a:splunk:splunk:9.4.8
  • Splunk » Splunk » Version: 9.4.9
    cpe:2.3:a:splunk:splunk:9.4.9


Contact Us

Shodan ® - All rights reserved