Description
Improper Neutralization. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Published: 2026-10-07
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is characterized as improper neutralization of input during web page generation, which is a form of cross‑site scripting. Splunk Enterprise allows untrusted input to be incorporated into web pages without adequate sanitization, enabling an attacker to inject arbitrary JavaScript. When executed in a victim’s browser, the script can steal session tokens, capture keystrokes, or modify page content, potentially compromising the confidentiality and integrity of the system.

Affected Systems

Affected systems are Splunk Enterprise customers using any of the following released versions: 10.4.3, 10.2.7, 10.0.10, or 9.4.15. All of these releases contain the underlying code paths that perform unsafe rendering of user‑supplied data. Users must upgrade to the specified corrected releases or newer to eliminate the flaw.

Risk and Exploitability

Risk and exploitability are elevated because the vulnerability is a classic web‑application weakness governed by CWE‑707. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, but common XSS exploitation techniques (e.g., malformed input in query parameters or custom dashboard widgets) suggest that the flaw is readily exploitable when users interact with the affected components. The attack vector is likely through the web interface, and depending on user privileges, an authenticated or unauthenticated attacker may be able to craft a payload that executes in the context of any logged‑in user who views the vulnerable page.

Generated by OpenCVE AI on October 7, 2026 at 23:11 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, 9.4.15, or a later release that contains the fix.
  • Restrict the ability to submit unsanitized data by disabling or limiting custom dashboard widgets that allow raw HTML input until a patch is applied.
  • Configure Splunk’s web security settings to enforce strict Content‑Security Policy headers, which block inline scripts and mitigate the impact of any residual XSS vectors.

Generated by OpenCVE AI on October 7, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Title Improper Neutralization in Splunk Enterprise
Weaknesses CWE-707
References

Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:39.281Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76284

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:20.117

Modified: 2026-10-07T21:17:20.117

Link: CVE-2026-76284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:15:08Z

Weaknesses