PT-2026-78773 · Splunk · Splunk Enterprise
CVE-2026-76346
·
Published
2026-08-19
·
Updated
2026-08-21
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.4.2
Splunk Enterprise versions prior to 10.2.6
Splunk Enterprise versions prior to 10.0.9
Splunk Enterprise versions prior to 9.4.14
Description
A user with the "power" role can store a malicious script within dashboard sparkline format options to execute unauthorized JavaScript in the browser of another user viewing the dashboard. If the victim has the "admin" role, the script can access all data available through Splunk Web and perform actions using those permissions. This occurs because Splunk Web fails to limit dashboard visualization options to safe settings and does not escape tooltip values before rendering. Exploitation requires the attacker to phish the target user into initiating a request within their browser.
Recommendations
Update to version 10.4.2 or later.
Update to version 10.2.6 or later.
Update to version 10.0.9 or later.
Update to version 9.4.14 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise