Cross-site request forgery in Splunk Enterprise - CVE-2026-76334
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SPL commands.
The vulnerability exists due to cross-site request forgery in Dashboard Studio workflow actions when submitting workflow-action URLs. A remote user can store a workflow action containing attacker-controlled SPL and trick another user into selecting it to run the SPL with that user's permissions.
Exploitation requires the power Splunk role.