Back

MEDIUM

SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk Enterprise

Published Aug 19, 2026

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authenticated user to run arbitrary Search Processing Language (SPL) searches on their behalf through the Event Type Builder. This could expose all relevant data and stored credentials. The vulnerability is possible when the Event Type Builder accepts cross-site request input and retains SPL-affecting values while building sample event searches. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Automatically find and build event types (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/9.0/event-types/automatically-find-and-build-event-types) in the Splunk documentation.

Affected products

Remediation

Vendor solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published Aug 19, 2026
Updated Aug 26, 2026
Reserved Aug 19, 2026
CISA Vulnrichment
Updated Aug 26, 2026
NVD
Status Analyzed
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner cisco
Published Aug 19, 2026
Updated Aug 26, 2026
Exploited since n/a
EUVD-2026-63127