Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Splunk HIGH 8.1
CVE-2026-76331

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject Sea…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 7.1
CVE-2026-76330

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a craf…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 6.4
CVE-2026-76329

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role …

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk MEDIUM 6.7
CVE-2026-76328

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Sear…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk MEDIUM 6.4
CVE-2026-76327

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unaut…

Fix: 3.8.70 / 3.9.23+
Fix from $4,000 2026-08-19
Splunk MEDIUM 5.7
CVE-2026-76326

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could store a da…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 7.3
CVE-2026-76325

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour know…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76324

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could create a malicious Splunk Web …

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 7.3
CVE-2026-76323

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could bypass Sea…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 8.0
CVE-2026-76322

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user" Splunk role could craft a Dashboard Studio dashbo…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 7.3
CVE-2026-76321

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could inject arbitrary Search Processing Language (SP…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 6.5
CVE-2026-76320

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authenticated user to run arbitrary Se…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 8.8
CVE-2026-76319

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perf…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76318

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could store a ma…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 8.8
CVE-2026-76317

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could move files…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 8.8
CVE-2026-76316

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port could store …

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 8.8
CVE-2026-76315

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute ar…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 8.8
CVE-2026-76314

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Re…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk HIGH 8.8
CVE-2026-76313

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Re…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk CRITICAL 9.4
CVE-2026-76312

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) sou…

Fix: 9.4.14 / 10.0.9+
Fix from $5,750 2026-08-19
Splunk CRITICAL 9.4
CVE-2026-76311

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the d…

Fix: 9.4.14 / 10.0.9+
Fix from $5,750 2026-08-19
Splunk CRITICAL 9.4
CVE-2026-76310

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the a…

Fix: 9.4.14 / 10.0.9+
Fix from $5,750 2026-08-19
Splunk MEDIUM 5.4
CVE-2026-76263

In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing La…

Fix: 10.2.6 / 10.4.2+
Fix from $4,000 2026-08-19
Splunk HIGH 7.5
CVE-2026-76262

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview s…

Fix: 10.4.2+
Fix from $4,900 2026-08-19
Splunk MEDIUM 6.5
CVE-2026-76261

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user w…

Fix: 3.8.70 / 3.9.23+
Fix from $4,000 2026-08-19
Splunk MEDIUM 6.5
CVE-2026-76260

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the rest_properties_get capability could read e…

Fix: 9.4.14 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 7.8
CVE-2026-76259

In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind t…

Fix: 9.3.14 / 9.4.13+
Fix from $4,900 2026-08-19
Splunk MEDIUM 6.5
CVE-2026-76258

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user …

Fix: 3.8.71 / 3.9.24+
Fix from $4,000 2026-08-19
Splunk MEDIUM 6.5
CVE-2026-76257

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user …

Fix: 3.8.71 / 3.9.24+
Fix from $4,000 2026-08-19
Splunk HIGH 7.3
CVE-2026-76255

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power" Splunk roles could trick anot…

Fix: 9.4.13 / 10.0.8+
Fix from $4,900 2026-08-19