Cross-site request forgery in Splunk Enterprise - CVE-2026-76334

 

Cross-site request forgery in Splunk Enterprise - CVE-2026-76334

Published: August 20, 2026


Vulnerability identifier: #VU144467
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76334
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SPL commands.

The vulnerability exists due to cross-site request forgery in Dashboard Studio workflow actions when submitting workflow-action URLs. A remote user can store a workflow action containing attacker-controlled SPL and trick another user into selecting it to run the SPL with that user's permissions.

Exploitation requires the power Splunk role.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76334

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins