PT-2026-78752 · Splunk · Splunk Enterprise
CVE-2026-76325
·
Published
2026-08-19
·
Updated
2026-08-26
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.4.2
Splunk Enterprise versions prior to 10.2.6
Splunk Enterprise versions prior to 10.0.9
Splunk Enterprise versions prior to 9.4.14
Description
A Cross-Site Scripting (XSS) issue exists where a user with the "power" role can store a malicious ui-tour knowledge object that matches an auto-tour page name and share it at the app level. This occurs because Splunk Web resolves auto-tour entries from the app namespace and utilizes untrusted tour content when constructing the tour image. Consequently, arbitrary JavaScript can be executed in the browser of another authenticated user visiting a standard Splunk Web page, potentially exposing sensitive data and compromising system integrity based on the victim's permissions.
Recommendations
Update to version 10.4.2 or later.
Update to version 10.2.6 or later.
Update to version 10.0.9 or later.
Update to version 9.4.14 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise