PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76334 Splunk CVE debrief

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the 'power' Splunk role could store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticated user selects the action from Event Actions and selects Continue, Splunk Enterprise runs the injected SPL using the permissions of that user. The vulnerability requires phishing the affected user to initiate a request within their browser. The affected product or component is Splunk Enterprise, and the vulnerability class is improper input validation. The likely operational impact is access or modification of data available to the user who runs the injected SPL. The source-confidence limits are based on the CVE record and NVD entry. The review context is that the vulnerability is possible because Dashboard Studio does not sufficiently validate workflow-action URLs before submitting requests.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-21
Advisory published
2026-08-19
Advisory updated
2026-08-21

Who should care

Splunk Enterprise administrators, users with the 'power' Splunk role, and authenticated users who may be targeted by phishing attacks are advised to take action. Affected operators include Splunk Enterprise users and administrators. The platform impact is that the vulnerability could allow access or modification of data available to the user who runs the injected SPL. Vulnerability-management teams should prioritize patching or mitigating the vulnerability. Security teams should educate users on phishing risks and safe browsing practices and monitor for suspicious Dashboard Studio workflow actions. Asset inventory and exposure review are recommended to identify potentially affected systems. Compensating controls, such as restricting 'power' Splunk role usage, should be considered while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Rollback and change window planning should be considered to minimize potential impact. Source tracking and logging should be reviewed to ensure that potential exploitation attempts can be identified and investigated. The goal is to prevent exploitation and minimize potential impact. The vulnerability-management team should prioritize patching or mitigating the vulnerability. The security team should educate users on phishing risks and safe browsing practices. The asset inventory team should identify potentially affected systems. The exposure review team should assess the potential impact of the vulnerability. The compensating controls team should consider restricting 'power' Splunk role usage. The monitoring team should review monitoring and detection capabilities. The rollback and change window planning team should plan for potential remediation. The source tracking team should review source tracking and logging capabilities. The defensive priority is to prevent exploitation and minimize potential impact. The recommended actions are to inventory and check for affected Splunk Enterprise versions, apply vendor patches or workarounds for vulnerable versions, monitor for suspicious Dashboard Studio workflow actions, restrict '

Technical summary

The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role could store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticated user selects the action from Event Actions and selects Continue, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user.

Defensive priority

Authenticated users with limited privileges could be tricked into running attacker-controlled Search Processing Language (SPL) using the permissions of that user, potentially allowing access or modification of data available to that user.

Recommended defensive actions

  • Inventory and check for affected Splunk Enterprise versions
  • Apply vendor patches or workarounds for vulnerable versions
  • Monitor for suspicious Dashboard Studio workflow actions
  • Restrict 'power' Splunk role usage
  • Educate users on phishing risks and safe browsing practices

Evidence notes

The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role could store a Dashboard Studio workflow action containing attacker-controlled SPL. Another authenticated user could then select the action and run the injected SPL using their permissions. The vulnerability requires phishing the affected user to initiate a request within their browser.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:17.840Z and has not been modified since then.