PT-2026-78773 · Splunk · Splunk Enterprise

CVE-2026-76346

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.2 Splunk Enterprise versions prior to 10.2.6 Splunk Enterprise versions prior to 10.0.9 Splunk Enterprise versions prior to 9.4.14
Description A user with the "power" role can store a malicious script within dashboard sparkline format options to execute unauthorized JavaScript in the browser of another user viewing the dashboard. If the victim has the "admin" role, the script can access all data available through Splunk Web and perform actions using those permissions. This occurs because Splunk Web fails to limit dashboard visualization options to safe settings and does not escape tooltip values before rendering. Exploitation requires the attacker to phish the target user into initiating a request within their browser.
Recommendations Update to version 10.4.2 or later. Update to version 10.2.6 or later. Update to version 10.0.9 or later. Update to version 9.4.14 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76346

Affected Products

Splunk Enterprise