Splunk / Splunk Cloud Platform
111 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-20298 | Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise | MEDIUM | 6.5 | Jul 15, 2026 |
| CVE-2026-20296 | SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise | HIGH | 8.3 | Jul 15, 2026 |
| CVE-2026-20297 | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise | HIGH | 7.2 | Jul 15, 2026 |
| CVE-2026-20258 | Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise | HIGH | 7.1 | Jun 10, 2026 |
| CVE-2026-20252 | Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise | HIGH | 7.6 | Jun 10, 2026 |
| CVE-2026-20257 | Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise | MEDIUM | 5.7 | Jun 10, 2026 |
| CVE-2026-20259 | Improper Access Control in Splunk Enterprise | MEDIUM | 5.5 | Jun 10, 2026 |
| CVE-2026-20255 | Improper Input Validation through Classic Dashboards in Splunk Enterprise | MEDIUM | 5.7 | Jun 10, 2026 |
| CVE-2026-20251 | Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway | HIGH | 8.8 | Jun 10, 2026 |
| CVE-2026-20254 | Information Disclosure through External Content Restriction Bypass in Splunk Enterprise | MEDIUM | 5.7 | Jun 10, 2026 |
| CVE-2026-20256 | Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise | MEDIUM | 5.7 | Jun 10, 2026 |
| CVE-2026-20239 | Sensitive Information Disclosure through Log Files in Splunk Enterprise | HIGH | 7.5 | May 20, 2026 |
| CVE-2026-20240 | Denial of Service through coldToFrozen.sh Script in Splunk Enterprise | HIGH | 7.1 | May 20, 2026 |
| CVE-2026-20203 | Improper Access Control in Data Model Acceleration in Splunk Enterprise | MEDIUM | 4.3 | Apr 15, 2026 |
| CVE-2026-20204 | Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise | HIGH | 7.1 | Apr 15, 2026 |
| CVE-2026-20202 | Improper Input Validation during User Account Creation in Splunk Enterprise | MEDIUM | 6.6 | Apr 15, 2026 |
| CVE-2026-20163 | Remote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk Enterprise | HIGH | 8.0 | Mar 11, 2026 |
| CVE-2026-20162 | Stored Cross-Site Scripting (XSS) through Path Traversal in Splunk Enterprise | MEDIUM | 6.3 | Mar 11, 2026 |
| CVE-2026-20166 | Sensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk Enterprise | MEDIUM | 5.4 | Mar 11, 2026 |
| CVE-2026-20164 | Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise | MEDIUM | 6.5 | Mar 11, 2026 |
| CVE-2026-20165 | Sensitive Information Disclosure in MongoClient logging channel in Splunk Enterprise | MEDIUM | 6.5 | Mar 11, 2026 |
| CVE-2026-20139 | Client-Side Denial of Service (DoS) through ''/splunkd/__raw/services/authentication/users/username'' REST API endpoint in Splunk Enterprise | MEDIUM | 4.3 | Feb 18, 2026 |
| CVE-2026-20144 | Sensitive Information Disclosure in ''_internal'' index in Splunk Enterprise | MEDIUM | 6.8 | Feb 18, 2026 |
| CVE-2026-20137 | Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk Enterprise | MEDIUM | 5.7 | Feb 18, 2026 |
| CVE-2025-20388 | Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise | LOW | 2.7 | Dec 3, 2025 |
Showing 1 to 25 of 111 CVEs