Junglewise Threat Intelligence

CVE-2026-76333: Splunk Enterprise stored XSS in Dashboard Studio workflow actions

CVE-2026-76333 · Severity: high · CVSS 7.1 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise is a data analytics and monitoring platform used by organizations to search, analyze, and visualize log data. A user with power-level privileges can create malicious workflow actions in Dashboard Studio that execute attacker-controlled JavaScript in the browsers of other authenticated users who interact with them. This could allow theft of session credentials, manipulation of search queries, or unauthorized access to sensitive data visible in Splunk Web.

Technical details

CVE-2026-76333 is a stored cross-site scripting (XSS) vulnerability in Splunk Enterprise's Dashboard Studio workflow-action functionality. The root cause is insufficient URL validation before processing workflow-action URLs; an attacker with the "power" role can craft a malicious URL containing JavaScript and store it as a workflow action. When another authenticated user clicks the action and selects "Continue," the JavaScript executes in their browser context with access to their Splunk session. The attack requires social engineering (phishing the victim user), but does not require escalated privileges on the attacker's part beyond the "power" role. Patches are available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.

Affected products

  • Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, 9.4.14

Timeline

  • 2026-08-19: disclosed

References