Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticated user selects the action from Event Actions and selects Continue, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user. The vulnerability is possible because Dashboard Studio does not sufficiently validate workflow-action URLs before submitting requests. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will.
Published: 2026-08-19
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability allows a user with the power role to store a workflow action that contains attacker‑controlled SPL. When another authenticated user selects that action from the Event Actions menu, the stored SPL is executed with the permissions of the user who initiates the request. The injected SPL can read or alter data that the initiating user can normally access, effectively bypassing normal role‑based boundaries. This flaw is described as a Cross‑Site Request Forgery (CWE‑352) due to inadequate validation of workflow‑action URLs.

Affected Systems

Splunk Enterprise instances running any version earlier than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are affected. The issue exists only when the Splunk Web interface is enabled, as it is the channel through which the vulnerable workflow actions are triggered.

Risk and Exploitability

The CVSS score of 6.4 indicates medium severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector requires the attacker to first create a malicious workflow action (by exploiting the power role) and then phish an authenticated user into selecting that action within their browser. This chain of events demonstrates that exploitation depends on user interaction and the presence of Splunk Web. The recommended resolution is to upgrade to a patched release (10.4.2 or later, 10.2.6 or later, 10.0.9 or later, or 9.4.14 or later) or, as an interim measure, disable Splunk Web so the vulnerable feature cannot be used.

Generated by OpenCVE AI on August 20, 2026 at 11:19 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

The vulnerability affects instances with Splunk Web turned on. Turning Splunk Web off is a possible workaround. See [Disable unnecessary Splunk Enterprise components](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/install-splunk-enterprise-securely/disable-unnecessary-splunk-enterprise-components) and the [web.conf](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/web.conf) configuration specification file for more information on turning off Splunk Web.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to a version that contains the fix (10.4.2 or newer, 10.2.6 or newer, 10.0.9 or newer, or 9.4.14 or newer).
  • If upgrading immediately is not feasible, disable Splunk Web to prevent use of the vulnerable Dashboard Studio workflow actions.
  • Remove or review existing custom workflow actions; delete any suspicious ones.

Generated by OpenCVE AI on August 20, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticated user selects the action from Event Actions and selects Continue, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user. The vulnerability is possible because Dashboard Studio does not sufficiently validate workflow-action URLs before submitting requests. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will.
Title SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:58.425Z

Reserved: 2026-08-19T12:02:03.627Z

Link: CVE-2026-76334

cve-icon Vulnrichment

Updated: 2026-08-27T16:17:34.724Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:17.840

Modified: 2026-08-27T17:20:15.227

Link: CVE-2026-76334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:30:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)