PatchSiren cyber security CVE debrief
CVE-2026-76334 Splunk CVE debrief
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the 'power' Splunk role could store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticated user selects the action from Event Actions and selects Continue, Splunk Enterprise runs the injected SPL using the permissions of that user. The vulnerability requires phishing the affected user to initiate a request within their browser. The affected product or component is Splunk Enterprise, and the vulnerability class is improper input validation. The likely operational impact is access or modification of data available to the user who runs the injected SPL. The source-confidence limits are based on the CVE record and NVD entry. The review context is that the vulnerability is possible because Dashboard Studio does not sufficiently validate workflow-action URLs before submitting requests.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Splunk Enterprise administrators, users with the 'power' Splunk role, and authenticated users who may be targeted by phishing attacks are advised to take action. Affected operators include Splunk Enterprise users and administrators. The platform impact is that the vulnerability could allow access or modification of data available to the user who runs the injected SPL. Vulnerability-management teams should prioritize patching or mitigating the vulnerability. Security teams should educate users on phishing risks and safe browsing practices and monitor for suspicious Dashboard Studio workflow actions. Asset inventory and exposure review are recommended to identify potentially affected systems. Compensating controls, such as restricting 'power' Splunk role usage, should be considered while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Rollback and change window planning should be considered to minimize potential impact. Source tracking and logging should be reviewed to ensure that potential exploitation attempts can be identified and investigated. The goal is to prevent exploitation and minimize potential impact. The vulnerability-management team should prioritize patching or mitigating the vulnerability. The security team should educate users on phishing risks and safe browsing practices. The asset inventory team should identify potentially affected systems. The exposure review team should assess the potential impact of the vulnerability. The compensating controls team should consider restricting 'power' Splunk role usage. The monitoring team should review monitoring and detection capabilities. The rollback and change window planning team should plan for potential remediation. The source tracking team should review source tracking and logging capabilities. The defensive priority is to prevent exploitation and minimize potential impact. The recommended actions are to inventory and check for affected Splunk Enterprise versions, apply vendor patches or workarounds for vulnerable versions, monitor for suspicious Dashboard Studio workflow actions, restrict '
Technical summary
The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role could store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticated user selects the action from Event Actions and selects Continue, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user.
Defensive priority
Authenticated users with limited privileges could be tricked into running attacker-controlled Search Processing Language (SPL) using the permissions of that user, potentially allowing access or modification of data available to that user.
Recommended defensive actions
- Inventory and check for affected Splunk Enterprise versions
- Apply vendor patches or workarounds for vulnerable versions
- Monitor for suspicious Dashboard Studio workflow actions
- Restrict 'power' Splunk role usage
- Educate users on phishing risks and safe browsing practices
Evidence notes
The vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role could store a Dashboard Studio workflow action containing attacker-controlled SPL. Another authenticated user could then select the action and run the injected SPL using their permissions. The vulnerability requires phishing the affected user to initiate a request within their browser.
Official resources
-
CVE-2026-76334 CVE record
CVE.org
-
CVE-2026-76334 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:17.840Z and has not been modified since then.