CVE-2026-76346
Analyzed Analyzed - Analysis Complete

Stored XSS in Splunk Enterprise Dashboard Visualizations

Vulnerability report for CVE-2026-76346, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-21

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user who views the dashboard. If the other user holds the "admin" Splunk role, the script could access all relevant data available through Splunk Web and perform actions with that user's permissions. The vulnerability is possible because Splunk Web does not limit the permitted dashboard visualization options to safe presentation settings and does not escape tooltip values before rendering them. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-21
Generated
2026-09-10
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
splunk splunk From 10.0.0 (inc) to 10.0.9 (exc)
splunk splunk From 10.2.0 (inc) to 10.2.6 (exc)
splunk splunk From 10.4.0 (inc) to 10.4.2 (exc)
splunk splunk From 9.4.0 (inc) to 9.4.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' role can store a malicious script in dashboard sparkline format options. When another user views the dashboard, the script executes unauthorized JavaScript in their browser. The issue occurs because Splunk Web does not restrict dashboard visualization options to safe settings and fails to escape tooltip values before rendering them.

Detection Guidance

To detect this vulnerability, check Splunk Enterprise versions for those below 10.4.2, 10.2.6, 10.0.9, or 9.4.14. Review dashboards for malicious scripts in sparkline format options, particularly those accessible by users with the 'power' role. Inspect browser console logs for unauthorized JavaScript execution when viewing dashboards.

Impact Analysis

If exploited, this vulnerability could allow an attacker to execute JavaScript in the browser of another user viewing a dashboard. If the affected user has the 'admin' role, the script could access all data available through Splunk Web and perform actions with admin permissions. The attacker must trick the user into initiating a request within their browser.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to sensitive data through cross-site scripting (XSS). If an attacker exploits this flaw, they could access data available to users with admin roles, which may include personal or health information. This unauthorized access could lead to data breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information.

Mitigation Strategies

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76346. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart