Splunk / Splunk Secure Gateway
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-76351 | Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway | HIGH | 8.8 | Aug 19, 2026 |
| CVE-2026-76347 | Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway | MEDIUM | 5.4 | Aug 19, 2026 |
| CVE-2026-76327 | SPL Injection through Splunk Web in Splunk Secure Gateway | MEDIUM | 6.4 | Aug 19, 2026 |
| CVE-2026-76261 | Insecure Default Access Control List through the REST API in Splunk Secure Gateway | MEDIUM | 6.5 | Aug 19, 2026 |
| CVE-2026-76258 | Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway | MEDIUM | 6.5 | Aug 19, 2026 |
| CVE-2026-76257 | Missing Authorization through REST API Endpoints in Splunk Secure Gateway | MEDIUM | 6.5 | Aug 19, 2026 |
| CVE-2026-76256 | Information Exposure through REST API Endpoints in Splunk Secure Gateway | MEDIUM | 4.3 | Aug 19, 2026 |
| CVE-2026-20251 | Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway | HIGH | 8.8 | Jun 10, 2026 |
| CVE-2025-20389 | Improper Input Validation in "label" column field in Splunk Secure Gateway App | MEDIUM | 6.5 | Dec 3, 2025 |
| CVE-2025-20383 | Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app | MEDIUM | 4.3 | Dec 3, 2025 |
| CVE-2025-20230 | Missing Access Control and Incorrect Ownership of Data in App Key Value Store (KVStore) collections in the Splunk Secure Gateway App | MEDIUM | 6.5 | Mar 26, 2025 |
| CVE-2025-20231 | Sensitive Information Disclosure in Splunk Secure Gateway App | HIGH | 7.1 | Mar 26, 2025 |
| CVE-2024-53243 | Information Disclosure in Mobile Alert Responses in Splunk Secure Gateway | MEDIUM | 4.3 | Dec 10, 2024 |
| CVE-2024-53247 | Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway app | HIGH | 8.8 | Dec 10, 2024 |
| CVE-2024-45735 | Improper Access Control for low-privileged user in Splunk Secure Gateway App | MEDIUM | 4.3 | Oct 14, 2024 |
Showing 1 to 15 of 15 CVEs