Cross-site scripting in Splunk Enterprise - CVE-2026-76252

 

Cross-site scripting in Splunk Enterprise - CVE-2026-76252

Published: August 20, 2026


Vulnerability identifier: #VU144430
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-76252
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute unauthorized JavaScript in another user's browser.

The vulnerability exists due to cross-site scripting in Splunk Web message validation when handling page messages. A remote attacker can trick a user into visiting a malicious web page to execute unauthorized JavaScript in that user's browser.

The unauthenticated user should not be able to exploit the vulnerability at will.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76252

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins