Cross-site scripting in Splunk Enterprise - CVE-2026-76325
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in Splunk Web auto-tour handling when resolving ui-tour knowledge objects from the app namespace. A remote user can store and share a malicious ui-tour knowledge object to execute JavaScript when another user visits a standard Splunk Web page.
Exploitation requires the power Splunk role.