PT-2026-78761 · Splunk · Splunk Enterprise

CVE-2026-76334

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.2 Splunk Enterprise versions prior to 10.2.6 Splunk Enterprise versions prior to 10.0.9 Splunk Enterprise versions prior to 9.4.14
Description An issue exists where a user with the "power" role can store a Dashboard Studio workflow action containing malicious Search Processing Language (SPL), which is a proprietary language used by Splunk to perform searches and analyze data. The flaw occurs because Dashboard Studio fails to sufficiently validate workflow-action URLs before submitting requests. An attacker can exploit this by tricking an authenticated user into initiating a request via phishing; when the victim selects the action from Event Actions and clicks Continue, the injected SPL executes with the victim's permissions, potentially allowing the attacker to access or modify data available to that user.
Recommendations Update to version 10.4.2 or later. Update to version 10.2.6 or later. Update to version 10.0.9 or later. Update to version 9.4.14 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76334

Affected Products

Splunk Enterprise