Executive brief
Splunk Enterprise is a data analytics platform used to search, monitor, and analyze machine-generated data across organizations. A user with the "power" role can inject malicious search commands into a Dashboard Studio workflow action; when another authenticated user clicks the action, Splunk executes the injected commands using that user's permissions, allowing data access or modification. The attack requires social engineering to trick a user into initiating the action within their browser.
Technical details
The vulnerability is a stored SPL (Search Processing Language) injection in Dashboard Studio workflow actions caused by insufficient validation of workflow-action URLs. An attacker with the "power" Splunk role can store a malicious workflow action containing attacker-controlled SPL code. When an authenticated user selects the action from Event Actions and proceeds, Splunk Enterprise executes the injected SPL with the permissions of the clicked-through user. The attack vector requires user interaction (phishing/social engineering) and an authenticated attacker session with "power" role privileges. Patches are available in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
Affected products
- Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14
Timeline
- 2026-08-19: disclosed: CVE-2026-76334 disclosed by Splunk
- 2026-08-19: patched: Patches released for Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14