Cross-site scripting in Splunk Enterprise - CVE-2026-76252
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in Splunk Web message validation when handling page messages. A remote attacker can trick a user into visiting a malicious web page to execute unauthorized JavaScript in that user's browser.
The unauthenticated user should not be able to exploit the vulnerability at will.