Cross-Site Scripting Vulnerability in Splunk Enterprise
CVE-2026-76333

7.1HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76333?

In Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, users with the 'power' role can store malicious URLs in Dashboard Studio workflows. When another authenticated user interacts with these stored actions, it can lead to execution of attacker-controlled JavaScript in their browser. This flaw arises from insufficient validation of workflow-action URLs, necessitating the attacker to trick the victim into triggering a request within their own session. It is important for Splunk administrators to understand how to manage user roles effectively to mitigate such risks.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.