PatchSiren cyber security CVE debrief
CVE-2026-76333 Splunk CVE debrief
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user with the 'power' Splunk role can store a Dashboard Studio workflow action with a crafted URL. When another authenticated user selects the stored action, attacker-controlled JavaScript runs in the browser of that user, potentially exposing data or actions available through Splunk Web. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. This could lead to security breaches if not properly mitigated. Therefore, prompt action is necessary to protect against potential attacks. Security teams should prioritize patching affected systems and implementing compensating controls to minimize exposure. Furthermore, asset inventory management is crucial to identify and address all affected systems within the organization. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their Splunk Enterprise deployments from potential attacks. Regular monitoring and detection capabilities should also be reviewed to ensure timely identification of any exploitation attempts. Overall, a comprehensive approach is required to address this vulnerability effectively and minimize its impact on the organization's security posture.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Splunk Enterprise administrators, users with the 'power' Splunk role, and security teams monitoring for potential JavaScript execution vulnerabilities should be aware of this vulnerability. They should validate and restrict workflow-action URLs to prevent potential JavaScript execution and limit the 'power' Splunk role to trusted users. Additionally, they should monitor for suspicious workflow actions in Splunk Enterprise and educate users on the risks of selecting unknown workflow actions. This vulnerability could expose data or actions available through Splunk Web to unauthorized users, potentially leading to security breaches if not properly mitigated. Therefore, prompt action is necessary to protect against potential attacks. Security teams should prioritize patching affected systems and implementing compensating controls to minimize exposure. Furthermore, asset inventory management is crucial to identify and address all affected systems within the organization. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their Splunk Enterprise deployments from potential attacks. Regular monitoring and detection capabilities should also be reviewed to ensure timely identification of any exploitation attempts. Overall, a comprehensive approach is required to address this vulnerability effectively and minimize its impact on the organization's security posture. The vulnerability's impact on the organization depends on the effectiveness of its current security controls and its ability to detect and respond to potential threats. Therefore, it is essential to have a thorough understanding of the vulnerability and its potential consequences to take appropriate measures to mitigate its effects. This includes reviewing and updating incident response plans to address potential exploitation of this vulnerability. By doing so, organizations can ensure they are prepared to respond quickly and effectively in the event of an attack. In addition to these measures, it is also important to consider the potential operational impact of this vulnerability on the organization. This includes assessing the likelihood of exploitation and 7
Technical summary
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user with the 'power' Splunk role can store a Dashboard Studio workflow action with a crafted URL. When another authenticated user selects the stored action, attacker-controlled JavaScript runs in the browser of that user, potentially exposing data or actions available through Splunk Web. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser.
Defensive priority
Splunk Enterprise users with the 'power' role should validate and restrict workflow-action URLs to prevent potential JavaScript execution.
Recommended defensive actions
- Validate and restrict workflow-action URLs in Splunk Enterprise Dashboard Studio
- Limit the 'power' Splunk role to trusted users
- Monitor for suspicious workflow actions in Splunk Enterprise
- Educate users on the risks of selecting unknown workflow actions
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Review asset inventory to identify and address all affected systems within the organization
- Track exceptions and retest remediated assets
Evidence notes
The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role could store a Dashboard Studio workflow action with a crafted URL. When another authenticated user selects the stored action, attacker-controlled JavaScript runs in the browser of that user. Evidence is limited to the CVE description and NVD detail. Defenders should verify affected scope, severity, and vendor guidance.
Official resources
-
CVE-2026-76333 CVE record
CVE.org
-
CVE-2026-76333 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:17.673Z and has not been modified since then.