Cross-site scripting in Splunk Enterprise - CVE-2026-76326
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute unauthorized JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in the dashboard table renderer when handling sparkline tooltip options. A remote user can store a dashboard view that executes JavaScript when another user opens it and hovers over a sparkline table cell.