SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76252

MEDIUM · CVSS 6.8 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.13 are susceptible to a Cross-Site Scripting (XSS) vulnerability that allows an unauthenticated attacker to execute unauthorized JavaScript in a victim's browser by tricking them into visiting a malicious web page. This exploitation can lead to unauthorized access to sensitive data and potential actions that compromise system integrity. Organizations using affected versions should prioritize patching to mitigate the risk of phishing attacks targeting their users.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76252
Severity
MEDIUM
CVSS
6.8
EPSS
0.18%
Java

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user into visiting a malicious web page could run unauthorized JavaScript in that user's browser. This could allow for unauthorized access to all relevant data available to that user and actions that affect system integrity. The Cross-Site Scripting (XSS) is possible because Splunk Web does not validate the origin and source of messages received by a page message handler. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will.

Related CVEs

Other vulnerabilities affecting the same vendor(s)