PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76325 Splunk CVE debrief

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a Cross-Site Scripting (XSS) vulnerability exists. A user with the 'power' Splunk role can store a malicious ui-tour knowledge object that matches an auto-tour page name and share it at the app level. This object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page, potentially exposing all relevant data and affecting system integrity within the second user's permissions. The vulnerability is possible because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image. To mitigate this vulnerability, Splunk Enterprise administrators and users with the 'power' role should verify and limit ui-tour knowledge object sharing.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-21
Advisory published
2026-08-19
Advisory updated
2026-08-21

Who should care

Splunk Enterprise administrators and users with the 'power' role should be aware of this vulnerability and take necessary actions to mitigate it. They should verify and limit ui-tour knowledge object sharing to trusted users and contexts, restrict the 'power' Splunk role to only necessary users, and monitor for suspicious ui-tour knowledge object creations and updates. Additionally, they should implement additional security measures to detect and prevent XSS attacks and apply the vendor-provided patches for affected Splunk Enterprise versions. IT security teams and vulnerability management teams should also be aware of this vulnerability and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset owners and operators of Splunk Enterprise should also prioritize patching and take immediate action to protect against potential threats. Security teams should ensure that incident response plans are in place in case of an attack. All these stakeholders should work together to ensure the timely mitigation of this vulnerability and minimize potential damage. The CVE details a Cross-Site Scripting (XSS) vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and affected users should take immediate action to protect against potential threats. This might require coordination with IT operations, security teams, and other stakeholders to ensure effective mitigation and minimize potential damage from an attack. Therefore, it is crucial for all relevant stakeholders to be aware of this vulnerability and take necessary actions to mitigate it effectively and efficiently. In conclusion, Splunk Enterprise administrators, users with the 'power' role, IT security teams, ,

Technical summary

A Cross-Site Scripting (XSS) vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store a malicious ui-tour knowledge object that matches an auto-tour page name and share it at the app level. When another authenticated user visits a standard Splunk Web page, the object can execute arbitrary JavaScript in their browser, potentially exposing all relevant data and affecting system integrity within the second user's permissions.

Defensive priority

Splunk Enterprise users with the 'power' role should verify and limit ui-tour knowledge object sharing.

Recommended defensive actions

  • Verify and limit ui-tour knowledge object sharing to trusted users and contexts.
  • Restrict the 'power' Splunk role to only necessary users.
  • Monitor for suspicious ui-tour knowledge object creations and updates.
  • Implement additional security measures to detect and prevent XSS attacks.
  • Apply the vendor-provided patches for affected Splunk Enterprise versions.

Evidence notes

The CVE details a Cross-Site Scripting (XSS) vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store malicious ui-tour knowledge objects that can execute arbitrary JavaScript in another authenticated user's browser. The vulnerability exists because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:16.650Z and has not been modified since then.