PatchSiren cyber security CVE debrief
CVE-2026-76325 Splunk CVE debrief
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a Cross-Site Scripting (XSS) vulnerability exists. A user with the 'power' Splunk role can store a malicious ui-tour knowledge object that matches an auto-tour page name and share it at the app level. This object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page, potentially exposing all relevant data and affecting system integrity within the second user's permissions. The vulnerability is possible because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image. To mitigate this vulnerability, Splunk Enterprise administrators and users with the 'power' role should verify and limit ui-tour knowledge object sharing.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Splunk Enterprise administrators and users with the 'power' role should be aware of this vulnerability and take necessary actions to mitigate it. They should verify and limit ui-tour knowledge object sharing to trusted users and contexts, restrict the 'power' Splunk role to only necessary users, and monitor for suspicious ui-tour knowledge object creations and updates. Additionally, they should implement additional security measures to detect and prevent XSS attacks and apply the vendor-provided patches for affected Splunk Enterprise versions. IT security teams and vulnerability management teams should also be aware of this vulnerability and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset owners and operators of Splunk Enterprise should also prioritize patching and take immediate action to protect against potential threats. Security teams should ensure that incident response plans are in place in case of an attack. All these stakeholders should work together to ensure the timely mitigation of this vulnerability and minimize potential damage. The CVE details a Cross-Site Scripting (XSS) vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and affected users should take immediate action to protect against potential threats. This might require coordination with IT operations, security teams, and other stakeholders to ensure effective mitigation and minimize potential damage from an attack. Therefore, it is crucial for all relevant stakeholders to be aware of this vulnerability and take necessary actions to mitigate it effectively and efficiently. In conclusion, Splunk Enterprise administrators, users with the 'power' role, IT security teams, ,
Technical summary
A Cross-Site Scripting (XSS) vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store a malicious ui-tour knowledge object that matches an auto-tour page name and share it at the app level. When another authenticated user visits a standard Splunk Web page, the object can execute arbitrary JavaScript in their browser, potentially exposing all relevant data and affecting system integrity within the second user's permissions.
Defensive priority
Splunk Enterprise users with the 'power' role should verify and limit ui-tour knowledge object sharing.
Recommended defensive actions
- Verify and limit ui-tour knowledge object sharing to trusted users and contexts.
- Restrict the 'power' Splunk role to only necessary users.
- Monitor for suspicious ui-tour knowledge object creations and updates.
- Implement additional security measures to detect and prevent XSS attacks.
- Apply the vendor-provided patches for affected Splunk Enterprise versions.
Evidence notes
The CVE details a Cross-Site Scripting (XSS) vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store malicious ui-tour knowledge objects that can execute arbitrary JavaScript in another authenticated user's browser. The vulnerability exists because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image.
Official resources
-
CVE-2026-76325 CVE record
CVE.org
-
CVE-2026-76325 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:16.650Z and has not been modified since then.