Junglewise Threat Intelligence

CVE-2026-76346: Splunk Enterprise stored XSS in dashboard sparkline tooltips

CVE-2026-76346 · Severity: medium · CVSS 5.4 · Published 2026-08-19

Technologies: Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise allows authenticated users with the "power" role to inject malicious JavaScript into dashboard sparkline visualization settings, which executes in the browsers of other users viewing the dashboard. If an administrator views the compromised dashboard, the attacker can access sensitive data and perform administrative actions. The attack requires social engineering to trick a user into initiating a request, but represents a significant privilege escalation path from power user to administrative access.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Splunk Web's dashboard visualization layer. The vulnerability exists in the sparkline chart visualization component where tooltip values are not properly escaped before rendering. A user with the "power" Splunk role can inject malicious script payloads into the dashboard sparkline format options and save them to the dashboard. When another user views the dashboard, the unescaped JavaScript executes in their browser context with their permissions. The attack requires the victim to be phished into clicking a link that triggers the malicious dashboard view, but if successful and the victim holds an "admin" role, the attacker gains full access to Splunk Web data and functions. Patches are available in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14.

Affected products

  • Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Patches released in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14

References