CVE-2026-76346: Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user who views the dashboard. If the other user holds the "admin" Splunk role, the script could access all relevant data available through Splunk Web and perform actions with that user's permissions. The vulnerability is possible because Splunk Web does not limit the permitted dashboard visualization options to safe presentation settings and does not escape tooltip values before rendering them. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.2 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.6 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.14
Event History
Frequently Asked Questions
Which users are realistically exposed to this issue?
A user with the Splunk "power" role can create the malicious dashboard content, but exploitation requires another user to view the dashboard and be tricked into initiating a request in their browser. The greatest impact occurs when the viewing user has the "admin" role, because the script can access Splunk Web data and perform actions available to that administrator.
Can a power-role user exploit this against viewers without additional interaction?
No. The power-role user cannot exploit the issue at will; they must phish the affected viewer into initiating a request in that viewer's browser after the malicious dashboard content has been stored.
Which releases are affected and which releases contain the fix?
Affected releases are Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Updating to the applicable listed version or later addresses the issue.
What dashboard content should be investigated for possible exposure?
Review dashboard sparkline format options, particularly tooltip values, for unexpected or malicious script content. The issue results from unsafe visualization options being permitted and tooltip values not being escaped before rendering.