Improper Input Validation in Splunk Enterprise Dashboard Studio
CVE-2026-76334
6.4MEDIUM
What is CVE-2026-76334?
In Splunk Enterprise, users with the 'power' role can create workflow actions in Dashboard Studio that include maliciously crafted Search Processing Language (SPL). If an authenticated user activates this action, the system runs the injected SPL with their permissions, potentially allowing unauthorized access to sensitive data. This vulnerability arises from insufficient validation of workflow-action URLs, enabling attackers to exploit it through user phishing techniques, requiring user action to trigger the attack.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9