Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-76321] SPL Injection through Nearby Event Searches in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could inject arbitrary Search Processing Language (SPL) into requests that search for events near a selected event. This could allow for unauthorized search execution. The vulnerability is possible because Splunk Web does not consistently escape caller-supplied values when it builds SPL for nearby-event searches, and embedded report access accepts those requests without the expected authorization check. For more information see Use time to find nearby events ( ) in the Splunk documentation.
High [CVE-2026-76319] Remote Code Execution (RCE) through Federated Search in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution through Federated Search bundle selection. This could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Federated Search dispatch flow accepts caller-controlled bundle selection without enforcing the capability that manages federated providers and indexes. For more information see Security models for Federated Search for Splunk ( ) and Define roles on the Splunk platform with capabilities ( ) in the Splunk documentation.
High [CVE-2026-76317] Path Traversal through the Lookup Configuration REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could move files that the user account running Splunk Enterprise can read into a lookup that the user controls. The user could then access all relevant data and affect system integrity and availability on the search head. The vulnerability is possible because the lookup configuration endpoint does not resolve lookup source paths before checking whether they stay inside the allowed lookup staging area. For more information see About lookups ( ) and Define roles on the Splunk platform with capabilities ( ) in the Splunk documentation.
High [CVE-2026-76316] Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port could store a Search Processing Language (SPL) pipeline that runs when an administrator opens the Add Data forwarder workflow. The SPL pipeline could access all relevant data, affect system integrity, and affect availability of the Splunk platform instance. The SPL injection is possible because Deployment Server client identifiers are placed into dispatched searches without neutralizing special characters. Successful exploitation requires an administrator to open the affected Add Data forwarder workflow after the unauthenticated user registers a crafted Deployment Server client identity. For more information see Forward data ( ) and About agent management ( ) in the Splunk documentation.
High [CVE-2026-76315] Code Injection through Splunk Web Manager Configuration in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute arbitrary code on the Splunk platform instance through Splunk Web Manager Configuration. The user could then access all relevant data and affect system integrity and availability on the Splunk platform instance. The vulnerability is possible because Splunk Web Manager Configuration evaluates manager configuration values, and the Representational State Transfer (REST) API path for manager configuration does not require the permission that normally controls manager configuration writes. For more information see About configuring role-based user access ( ) and restmap.conf ( ) in the Splunk documentation.
High [CVE-2026-76314] Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect system integrity and availability. The vulnerability is possible because Splunk Web evaluates manager Extensible Markup Language expressions without sufficient input restrictions, and the associated configuration route does not require the capability expected for manager configuration changes. For more information see About configuration files ( ) in the Splunk documentation.
High [CVE-2026-76313] Remote Code Execution (RCE) through the REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Representational State Transfer (REST) API endpoint for knowledge bundle upload does not require the high-privilege capability edit_dist_peer, and distributed search accepts caller-supplied knowledge bundle selections from users who do not hold that capability. For more information see What search heads send to search peers ( ), About configuring role-based user access ( ), Define roles on the Splunk platform with capabilities ( ), and Using the REST API reference ( ) in the Splunk documentation.
High [CVE-2026-76262] Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk Enterprise
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is possible because the Prometheus metrics endpoint in the Edge Processor SPL2 Preview sidecar lacks authentication, which lets any client that can reach the sidecar retrieve the metrics without credentials. For more information see About Splunk sidecars ( ) in the Splunk documentation.
High [CVE-2026-76259] Improper Privilege Management on the Management Port in Splunk Enterprise for Windows
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all relevant data and system integrity available to the user account running Splunk Enterprise. The vulnerability is possible because the Windows management-port listener does not apply exclusive address binding protections before the service starts.
High [CVE-2026-76254] SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) pipelines from Dataset Explorer with the same privileges as that user, which can allow for access to all relevant data and system integrity available to that user and affect system availability. The vulnerability is possible because Dataset Explorer does not validate or escape dataset names before building SPL searches and does not apply SPL safeguards for risky commands to those searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Explore a dataset ( ) and SPL safeguards for risky commands ( ) in the Splunk documentation.
High [CVE-2026-76253] Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and availability. The vulnerability is possible because scheduled search alert action configuration does not properly restrict user-specific alert action settings before the search scheduler runs alert actions. For more information see Create scheduled alerts ( ), Set up alert actions ( ), Define roles on the Splunk platform with capabilities ( ), and Configuration file precedence ( ) in the Splunk documentation.
High [CVE-2026-76251] Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability Cloud
In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Splunk Observability Cloud access token stored for the app. With this access, the user could view all relevant data available to that token and make limited changes to Splunk Observability Cloud content. The vulnerability is possible because the app's Representational State Transfer (REST) API endpoint handlers do not enforce the read_o11y_content capability before forwarding requests with the stored access token. For more information see Define roles on the Splunk platform with capabilities ( ) in the Splunk documentation.
High [CVE-2026-76139] Bundle build execs unpinned stolostron/release@master with full build credentials
Bundle build execs unpinned stolostron/release@master with full build credentials. Red Hat rates this important (CVSS 8). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:60401 with package rhacm2/acm-operator-bundle:1787712120, rhacm2/acm-operator-bundle:1787738299, rhacm2/acm-operator-bundle:1787704547, rhacm2/acm-operator-bundle:1787711895. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-68553] Format string vulnerability leads to denial of service and information disclosure
Format string vulnerability leads to denial of service and information disclosure. Red Hat rates this important (CVSS 7.1). Weakness: CWE-134.
High [CVE-2026-75569] Bundle-generation business logic fetched from mutable stolostron/release@master
Bundle-generation business logic fetched from mutable stolostron/release@master. Red Hat rates this important (CVSS 7.7). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:59643 with package multicluster-engine/mce-operator-bundle:1787318262, multicluster-engine/mce-operator-bundle:1787321579, multicluster-engine/mce-operator-bundle:1787263075, multicluster-engine/mce-operator-bundle:1787317415. Affected product named by the advisory: Multicluster Engine for Kubernetes.
High [CVE-2026-63633] Arbitrary code execution via heap buffer overflow in Opus audio decode
Arbitrary code execution via heap buffer overflow in Opus audio decode. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.
High [CVE-2026-50152] MON subscription handler exposes config-key store to low-privilege CephX users
MON subscription handler exposes config-key store to low-privilege CephX users. Red Hat rates this important (CVSS 8.2). Weakness: CWE-862. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.
High [CVE-2026-54330] RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation
RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-347. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.
High [CVE-2026-39944] RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation
RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation. Red Hat rates this important (CVSS 8.5). Weakness: CWE-327. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.
High [CVE-2026-55192] Out-of-bounds read leads to memory disclosure or client crash
Out-of-bounds read leads to memory disclosure or client crash. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: freerdp.