Cross-Site Scripting Vulnerability in Splunk Enterprise
CVE-2026-76333
7.1HIGH
What is CVE-2026-76333?
In Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, users with the 'power' role can store malicious URLs in Dashboard Studio workflows. When another authenticated user interacts with these stored actions, it can lead to execution of attacker-controlled JavaScript in their browser. This flaw arises from insufficient validation of workflow-action URLs, necessitating the attacker to trick the victim into triggering a request within their own session. It is important for Splunk administrators to understand how to manage user roles effectively to mitigate such risks.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9