What is CVE-2026-76346?
In affected versions of Splunk Enterprise, a user with the "power" role can store a malicious script in dashboard sparkline format options, leading to unauthorized JavaScript execution in the browser of another user viewing the dashboard. Organizations using vulnerable versions should urgently apply the indicated security updates.
Azərbaycanca: CVE-2026-76346, Splunk Enterprise-in müəyyən versiyalarında "power" roluna malik istifadəçiyə dashboard sparkline format seçimlərində zərərli skript yerləşdirərək, dashboard-u görüntüləyən digər istifadəçinin brauzerində icazəsiz JavaScript icra etməyə imkan verir. Təsirə məruz qalan versiyaları istifadə edən təşkilatlar dərhal göstərilən təhlükəsizlik yamalarına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Splunk
FAQ2
What privilege level is required for the attacker?
To exploit this vulnerability, the attacker must have the 'power' role in Splunk Enterprise.
Where is the malicious script stored?
The malicious script is stored in dashboard sparkline format options.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.