Executive brief
Splunk Enterprise is a data analytics and monitoring platform used by organizations to search, analyze, and visualize log data. A user with power-level privileges can create malicious workflow actions in Dashboard Studio that execute attacker-controlled JavaScript in the browsers of other authenticated users who interact with them. This could allow theft of session credentials, manipulation of search queries, or unauthorized access to sensitive data visible in Splunk Web.
Technical details
CVE-2026-76333 is a stored cross-site scripting (XSS) vulnerability in Splunk Enterprise's Dashboard Studio workflow-action functionality. The root cause is insufficient URL validation before processing workflow-action URLs; an attacker with the "power" role can craft a malicious URL containing JavaScript and store it as a workflow action. When another authenticated user clicks the action and selects "Continue," the JavaScript executes in their browser context with access to their Splunk session. The attack requires social engineering (phishing the victim user), but does not require escalated privileges on the attacker's part beyond the "power" role. Patches are available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
Affected products
- Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, 9.4.14
Timeline
- 2026-08-19: disclosed