SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76325

HIGH · CVSS 7.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to a Cross-Site Scripting (XSS) flaw that allows users with the "power" role to create and share malicious ui-tour objects, which can execute arbitrary JavaScript in the browsers of other authenticated users. This could lead to unauthorized data exposure and compromise system integrity based on the permissions of the affected users. Organizations using affected versions of Splunk should prioritize patching to mitigate this high-severity vulnerability.

CVE
CVE-2026-76325
Severity
HIGH
CVSS
7.3
EPSS
0.25%
Java

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour knowledge object that matches an auto-tour page name and share the object at the app level. The object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page. The JavaScript could expose all relevant data and affect system integrity within the second user permissions. The Cross-Site Scripting (XSS) vulnerability is possible because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image.

Related CVEs

Other vulnerabilities affecting the same vendor(s)