JavaScript Injection Vulnerability in Splunk Enterprise by Splunk
CVE-2026-76346

5.4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76346?

In specific versions of Splunk Enterprise, a vulnerability allows users with the 'power' role to inject malicious scripts into dashboard visualizations. This exposes unsuspecting 'admin' users to unauthorized JavaScript execution, potentially accessing sensitive data and executing actions under their permissions. The flaw stems from inadequate safeguards in the dashboard configuration options, which fail to sanitize user inputs correctly. Attackers can exploit this vulnerability by tricking users into executing crafted requests within their browsers, heightening security risks for affected organizations.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.