Splunk / Splunk
264 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-76355 | Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk Enterprise | HIGH | 7.5 | Aug 19, 2026 |
| CVE-2026-76354 | Path Traversal through Search Head Clustering in Splunk Enterprise | HIGH | 8.1 | Aug 19, 2026 |
| CVE-2026-76353 | Path Traversal through Knowledge Bundle Replication in Splunk Enterprise | MEDIUM | 5.4 | Aug 19, 2026 |
| CVE-2026-76352 | Improper Authorization through the REST API in Splunk Enterprise | HIGH | 8.8 | Aug 19, 2026 |
| CVE-2026-76351 | Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway | HIGH | 8.8 | Aug 19, 2026 |
| CVE-2026-76350 | Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk Enterprise | HIGH | 8.8 | Aug 19, 2026 |
| CVE-2026-76349 | SPL Injection through Splunk Web Form Tokens in Splunk Enterprise | MEDIUM | 6.4 | Aug 19, 2026 |
| CVE-2026-76348 | Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise | LOW | 3.8 | Aug 19, 2026 |
| CVE-2026-76347 | Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway | MEDIUM | 5.4 | Aug 19, 2026 |
| CVE-2026-76346 | Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise | MEDIUM | 5.4 | Aug 19, 2026 |
| CVE-2026-76345 | Remote Code Execution (RCE) through the REST API in Splunk Enterprise | MEDIUM | 6.0 | Aug 19, 2026 |
| CVE-2026-76344 | Path Traversal through the Search Dispatch REST API in Splunk Enterprise | HIGH | 7.7 | Aug 19, 2026 |
| CVE-2026-76343 | Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise | MEDIUM | 6.5 | Aug 19, 2026 |
| CVE-2026-76342 | Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise | MEDIUM | 5.4 | Aug 19, 2026 |
| CVE-2026-76341 | Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk Enterprise | MEDIUM | 5.4 | Aug 19, 2026 |
| CVE-2026-76340 | Missing Authorization for Reloading Token-Signing Keys through the REST API in Splunk Enterprise | MEDIUM | 5.3 | Aug 19, 2026 |
| CVE-2026-76339 | SPL Injection through the geostats Command in Splunk Enterprise | MEDIUM | 5.4 | Aug 19, 2026 |
| CVE-2026-76338 | Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise | HIGH | 8.1 | Aug 19, 2026 |
| CVE-2026-76337 | Path Traversal through Splunk Web Static File Serving in Splunk Enterprise | MEDIUM | 5.3 | Aug 19, 2026 |
| CVE-2026-76336 | Improper Access Control through the REST API in Splunk Enterprise | HIGH | 7.1 | Aug 19, 2026 |
| CVE-2026-76335 | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise | HIGH | 8.8 | Aug 19, 2026 |
| CVE-2026-76334 | SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise | MEDIUM | 6.4 | Aug 19, 2026 |
| CVE-2026-76333 | Stored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk Enterprise | HIGH | 7.1 | Aug 19, 2026 |
| CVE-2026-76332 | SPL Injection through Splunk Web in Splunk Enterprise | HIGH | 7.1 | Aug 19, 2026 |
| CVE-2026-76331 | SPL Injection through the REST API in Splunk Enterprise | HIGH | 8.1 | Aug 19, 2026 |
Showing 1 to 25 of 264 CVEs