CVE-2026-76334: The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. in Splunk Splunk Enterprise
Description
CVE-2026-76334 affects Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. It allows a user with the "power" role to store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticated user triggers this action, the injected SPL executes with their permissions, potentially accessing or modifying their data. The vulnerability arises from insufficient validation of workflow-action URLs in Dashboard Studio and requires phishing to trick the victim into initiating the request.
CVSS v3.1
Score 6.4medium
Affected software
Splunk
Splunk Enterprise
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Splunk Enterprise occurs because Dashboard Studio does not properly validate workflow-action URLs before processing them. A user with the "power" role can embed malicious SPL in a workflow action. When another user selects this action and continues, the SPL runs with the victim's permissions, allowing unauthorized data access or modification. Exploitation requires social engineering (phishing) to induce the victim to trigger the malicious action. The "power" role user cannot exploit this vulnerability directly without victim interaction.
Potential Impact
An attacker with the "power" role can craft malicious SPL embedded in a Dashboard Studio workflow action. If an authenticated user is tricked into triggering this action, the SPL executes with their permissions, potentially leading to unauthorized data access or modification. This can compromise confidentiality and integrity of data accessible to the victim user. Availability is not impacted. The attack requires user interaction via phishing, limiting the ease of exploitation.
Mitigation Recommendations
A fix is available in Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Users should upgrade to these or later versions to remediate the vulnerability. Until patched, restrict the assignment of the "power" role to trusted users and educate users to be cautious of phishing attempts involving Dashboard Studio actions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2026-08-19T12:02:03.627Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a862255acd9273b49a6fe46
Added to database: 08/19/2026, 21:38:29 UTC
Last enriched: 09/11/2026, 07:04:06 UTC
Last updated: 10/04/2026, 10:04:20 UTC
Views: 41
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.