PT-2026-78761 · Splunk · Splunk Enterprise
CVE-2026-76334
·
Published
2026-08-19
·
Updated
2026-08-21
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.4.2
Splunk Enterprise versions prior to 10.2.6
Splunk Enterprise versions prior to 10.0.9
Splunk Enterprise versions prior to 9.4.14
Description
An issue exists where a user with the "power" role can store a Dashboard Studio workflow action containing malicious Search Processing Language (SPL), which is a proprietary language used by Splunk to perform searches and analyze data. The flaw occurs because Dashboard Studio fails to sufficiently validate workflow-action URLs before submitting requests. An attacker can exploit this by tricking an authenticated user into initiating a request via phishing; when the victim selects the action from Event Actions and clicks Continue, the injected SPL executes with the victim's permissions, potentially allowing the attacker to access or modify data available to that user.
Recommendations
Update to version 10.4.2 or later.
Update to version 10.2.6 or later.
Update to version 10.0.9 or later.
Update to version 9.4.14 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise