Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Soar MEDIUM 6.5
CVE-2026-76364

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) …

Fix: 8.6.0+
Fix from $4,000 2026-08-19
Soar MEDIUM 6.5
CVE-2026-76363

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL) statements a…

Fix: 8.6.0+
Fix from $4,000 2026-08-19
Soar HIGH 7.4
CVE-2026-76362

In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk R…

Fix: 8.6.0+
Fix from $4,900 2026-08-19
Soar MEDIUM 6.5
CVE-2026-76359

In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive …

Fix: 8.6.0+
Fix from $4,000 2026-08-19
Soar MEDIUM 6.5
CVE-2026-76358

In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the i…

Fix: 8.6.0+
Fix from $4,000 2026-08-19
Soar HIGH 7.6
CVE-2026-76357

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Trans…

Fix: 8.6.0+
Fix from $4,900 2026-08-19
Soar HIGH 8.1
CVE-2026-76356

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notificat…

Fix: 8.6.0+
Fix from $4,900 2026-08-19
Splunk HIGH 7.5
CVE-2026-76355

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configur…

Fix: 10.4.2+
Fix from $4,900 2026-08-19
Splunk HIGH 8.1
CVE-2026-76354

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect sys…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76353

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a c…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 8.8
CVE-2026-76352

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could create or …

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 8.8
CVE-2026-76351

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user w…

Fix: 3.8.70 / 3.9.23+
Fix from $4,900 2026-08-19
Splunk HIGH 8.8
CVE-2026-76350

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure …

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 6.4
CVE-2026-76349

In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running arbitrary Sear…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76347

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user w…

Fix: 3.8.70 / 3.9.23+
Fix from $4,000 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76346

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in da…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk MEDIUM 6.0
CVE-2026-76345

In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage search head clustering could use the search head…

Fix: 10.4.2+
Fix from $4,000 2026-08-19
Splunk HIGH 7.7
CVE-2026-76344

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write disp…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 6.5
CVE-2026-76343

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute at…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76342

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store risky Search Processing …

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76341

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Sear…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk MEDIUM 5.3
CVE-2026-76340

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Repre…

Fix: 10.4.2+
Fix from $4,000 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76339

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject arb…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 8.1
CVE-2026-76338

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search privat…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 5.3
CVE-2026-76337

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web st…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 7.1
CVE-2026-76336

In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processin…

Fix: 10.2.6 / 10.4.2+
Fix from $4,900 2026-08-19
Splunk HIGH 8.8
CVE-2026-76335

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capa…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 6.4
CVE-2026-76334

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workf…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 7.1
CVE-2026-76333

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workf…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 7.1
CVE-2026-76332

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a craf…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19