PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76346 Splunk CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:19.427Z and has not been modified since then. This vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user who views the dashboard. The vulnerability requires phishing the affected user by tricking them into initiating a request within their browser. If the other user holds the 'admin' Splunk role, the script could access all relevant data available through Splunk Web and perform actions with that user's permissions. The vulnerability is possible because Splunk Web does not limit permitted dashboard visualization options to safe presentation settings and does not escape tooltip values before rendering them. To mitigate, review and limit dashboard visualization options to safe presentation settings, ensure tooltip values are properly escaped before rendering, and restrict users with the 'power' Splunk role from storing malicious scripts.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-21
Advisory published
2026-08-19
Advisory updated
2026-08-21

Who should care

Splunk Enterprise administrators and users with the 'power' or 'admin' Splunk roles should be aware of this vulnerability and take steps to mitigate it. Affected operators should review and limit dashboard visualization options to safe presentation settings, ensure tooltip values are properly escaped before rendering, and restrict users with the 'power' Splunk role from storing malicious scripts. Vulnerability management and security teams should monitor for suspicious activity and implement compensating controls as needed. Platform administrators should educate users on the risks of phishing attacks and implement additional security measures to prevent exploitation. Asset inventory management should be reviewed to identify potentially affected systems. Rollback and change window procedures should be updated to address this vulnerability. Source tracking and monitoring should be implemented to detect potential exploitation attempts. This vulnerability may impact the confidentiality and integrity of data within Splunk Enterprise deployments, and defenders should prioritize mitigation efforts accordingly. Security teams should review the affected components and assess the potential operational impact on their organization. They should also verify that proper defensive measures are in place to prevent exploitation and limit the blast radius in case of a successful attack. The vulnerability's severity and potential impact on the organization should be carefully evaluated to ensure adequate prioritization of mitigation efforts. Defenders should focus on implementing compensating controls, monitoring for suspicious activity, and ensuring that affected systems are properly patched or mitigated. The vulnerability's technical details and potential attack vectors should be thoroughly understood to ensure effective mitigation and response. The affected systems and data should be carefully assessed to determine the potential impact and prioritize mitigation efforts accordingly. The organization's incident response plan should be updated to address this vulnerability and potential exploitation attempts. The security team should work closely with IT and development teams to确保

Technical summary

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user with the 'power' Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user who views the dashboard. This could allow an attacker to access sensitive data or perform actions with the permissions of the affected user. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser.

Defensive priority

Medium-priority defensive actions are required to address this issue, as an attacker with the 'power' Splunk role could exploit this vulnerability to execute unauthorized JavaScript in the browser of another user.

Recommended defensive actions

  • Review and limit dashboard visualization options to safe presentation settings
  • Ensure tooltip values are properly escaped before rendering
  • Restrict users with the 'power' Splunk role from storing malicious scripts
  • Educate users on the risks of phishing attacks
  • Monitor for suspicious activity and implement compensating controls

Evidence notes

Evidence is based on official CVE and NVD records, as well as a vendor advisory. The CVE description notes that Splunk Web does not limit permitted dashboard visualization options to safe presentation settings and does not escape tooltip values before rendering them. Additionally, defenders should verify the affected Splunk Enterprise versions and configurations, review dashboard sparkline format options for potential malicious scripts, and ensure proper escaping of tooltip values.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:19.427Z and has not been modified since then.