← Back

CVE-2026-76346

nvd nist
Published: Aug 19, 2026Modified: Aug 21, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
Exploitability: 1.2 / Impact: 4.2
Source: psirt@cisco.com (Secondary)

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user who views the dashboard. If the other user holds the "admin" Splunk role, the script could access all relevant data available through Splunk Web and perform actions with that user's permissions. The vulnerability is possible because Splunk Web does not limit the permitted dashboard visualization options to safe presentation settings and does not escape tooltip values before rendering them. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

Affected (4)

Products: Splunk: Splunk
1 product
Splunk
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 10.0.0 to 10.0.9
From 10.2.0 to 10.2.6
From 10.4.0 to 10.4.2
From 9.4.0 to 9.4.14

References (1)

Source: psirt@cisco.com
Vendor Advisory

Timeline

No history available yet.