Junglewise Threat Intelligence

CVE-2026-76334: Splunk Enterprise stored SPL injection through Dashboard Studio workflow actions

CVE-2026-76334 · Severity: medium · CVSS 6.4 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise is a data analytics platform used to search, monitor, and analyze machine-generated data across organizations. A user with the "power" role can inject malicious search commands into a Dashboard Studio workflow action; when another authenticated user clicks the action, Splunk executes the injected commands using that user's permissions, allowing data access or modification. The attack requires social engineering to trick a user into initiating the action within their browser.

Technical details

The vulnerability is a stored SPL (Search Processing Language) injection in Dashboard Studio workflow actions caused by insufficient validation of workflow-action URLs. An attacker with the "power" Splunk role can store a malicious workflow action containing attacker-controlled SPL code. When an authenticated user selects the action from Event Actions and proceeds, Splunk Enterprise executes the injected SPL with the permissions of the clicked-through user. The attack vector requires user interaction (phishing/social engineering) and an authenticated attacker session with "power" role privileges. Patches are available in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14.

Affected products

  • Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14

Timeline

  • 2026-08-19: disclosed: CVE-2026-76334 disclosed by Splunk
  • 2026-08-19: patched: Patches released for Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14

References