Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade Splunk Enterprise Security to 8.6.1 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0807 |
|
Thu, 20 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all relevant data and system integrity through those searches. The vulnerability is possible because the UEBA app metadata grants analyst roles write access to search macros that should be writable only by administrator roles. For more information see Users and roles for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/install/8.4/installation/users-and-roles-for-splunk-enterprise-security) and Roles and knowledge objects in UEBA for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.5/user-and-entity-behavior-analytics/roles-and-knowledge-objects-in-ueba-for-splunk-enterprise-security) in the Splunk documentation. | |
| Title | Privilege Escalation through Search Macro Permissions in Splunk Enterprise Security | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-08-20T13:18:14.252Z
Reserved: 2026-08-19T12:02:03.631Z
Link: CVE-2026-76388
Updated: 2026-08-20T13:18:11.012Z
Status : Awaiting Analysis
Published: 2026-08-19T22:17:25.090
Modified: 2026-08-20T14:17:59.213
Link: CVE-2026-76388
No data.
OpenCVE Enrichment
Updated: 2026-08-20T11:00:04Z