PatchSiren cyber security CVE debrief
CVE-2026-76325 Splunk CVE debrief
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a Cross-Site Scripting (XSS) vulnerability exists. A user with the 'power' Splunk role can store a malicious ui-tour knowledge object that matches an auto-tour page name and share it at the app level. This object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page, potentially exposing all relevant data and affecting system integrity within the second user's permissions. The vulnerability is possible because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image. To mitigate this vulnerability, Splunk Enterprise administrators and users with the 'power' role should verify and limit ui-tour knowledge object sharing.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-26
Who should care
Splunk Enterprise administrators and users with the 'power' role should be aware of this vulnerability and take necessary actions to mitigate it. They should verify and limit ui-tour knowledge object sharing to trusted users and contexts, restrict the 'power' Splunk role to only necessary users, and monitor for suspicious ui-tour knowledge object creations and updates. Additionally, they should implement additional security measures to detect and prevent XSS attacks and apply the vendor-provided patches for affected Splunk Enterprise versions. IT security teams and vulnerability management teams should also be aware of this vulnerability and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset owners and operators of Splunk Enterprise should also prioritize patching and take immediate action to protect against potential threats. Security teams should ensure that incident response plans are in place in case of an attack. All these stakeholders should work together to ensure the timely mitigation of this vulnerability and minimize potential damage. The CVE details a Cross-Site Scripting (XSS) vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and affected users should take immediate action to protect against potential threats. This might require coordination with IT operations, security teams, and other stakeholders to ensure effective mitigation and minimize potential damage from an attack. Therefore, it is crucial for all relevant stakeholders to be aware of this vulnerability and take necessary actions to mitigate it effectively and efficiently. In conclusion, Splunk Enterprise administrators, users with the 'power' role, IT security teams, ,
Technical summary
A Cross-Site Scripting (XSS) vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store a malicious ui-tour knowledge object that matches an auto-tour page name and share it at the app level. When another authenticated user visits a standard Splunk Web page, the object can execute arbitrary JavaScript in their browser, potentially exposing all relevant data and affecting system integrity within the second user's permissions.
Defensive priority
Splunk Enterprise users with the 'power' role should verify and limit ui-tour knowledge object sharing.
Recommended defensive actions
- Verify and limit ui-tour knowledge object sharing to trusted users and contexts.
- Restrict the 'power' Splunk role to only necessary users.
- Monitor for suspicious ui-tour knowledge object creations and updates.
- Implement additional security measures to detect and prevent XSS attacks.
- Apply the vendor-provided patches for affected Splunk Enterprise versions.
Evidence notes
The CVE details a Cross-Site Scripting (XSS) vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store malicious ui-tour knowledge objects that can execute arbitrary JavaScript in another authenticated user's browser. The vulnerability exists because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76325 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76325
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76325 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76325
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-0801
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.