Skip to content
VulniPulse

Splunk Splunk Enterprise Vulnerabilities & Security Advisories

185 advisories tracked · Splunk (prodsec@splunk.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Splunk advisory that VulniPulse classified as Splunk Enterprise, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 81 high, 90 medium, 4 low.

Android app · Google Play

Monitor Splunk CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

Splunk (prodsec@splunk.com CNA) via NVD

Splunk is its own CVE Numbering Authority. VulniPulse ingests Splunk's CVEs from the NVD CNA feed (prodsec@splunk.com), each linking to its SVD-YYYY-NNNN advisory on advisory.splunk.com. Covers Splunk Enterprise, Splunk Cloud Platform, the Universal Forwarder, IT Service Intelligence (ITSI), SOAR, Enterprise Security and Splunk apps/add-ons — the SIEM at the centre of most SOCs, so a security-team audience that patches on advisory day.

Latest Splunk Splunk Enterprise advisories

Medium6.3Splunk

Medium [CVE-2026-76280] Incorrect Permission Assignment for App Key Value Store Collections in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the "admin" or "sc_admin" Splunk roles could modify Splunk Secure Gateway alert and mobile-device recipient data in App Key Value Store (KV Store) collections that later alert and subscription workflows use. The vulnerability is possible because the affected collections allow unrestricted write access instead of limiting writes to authorized Splunk Secure Gateway workflows. For more information see About the app key value store ( ), KV store endpoint descriptions ( ), and About configuring role-based user access ( ) in the Splunk documentation.

CVE-2026-76280
Splunk Enterprise
Oct 7, 2026
Medium4.3Splunk

Medium [CVE-2026-76279] Improper Input Validation of Index Names through the collect Command in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to write events to internal indexes outside the index access configured for the role. The vulnerability is possible because Splunk Enterprise does not normalize whitespace in an index name before applying configured index-access restrictions for the role. For more information see collect ( ), Define roles on the Splunk platform with capabilities ( ), and How indexing works ( ) in the Splunk documentation.

CVE-2026-76279
Splunk Enterprise
Oct 7, 2026
Medium4.3Splunk

Medium [CVE-2026-76278] Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State Transfer (REST) API to access permission grants for SPL2 modules that the user does not have permission to view. The vulnerability is possible because Splunk Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. For more information see Module permissions ( ) and Manage SPL2 modules ( ) in the Splunk documentation.

CVE-2026-76278
Splunk Enterprise
Oct 7, 2026
Medium4.1Splunk

Medium [CVE-2026-76277] Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication ( ) and Define roles on the Splunk platform with capabilities ( ) in the Splunk documentation.

CVE-2026-76277
Splunk Enterprise
Oct 7, 2026
Medium4.3Splunk

Medium [CVE-2026-76276] Information Disclosure in the Discover Splunk Observability Cloud app through Splunk Web for Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web. The vulnerability is possible because production JavaScript bundles for the app contain embedded source maps that include original source code. For more information see About configuring role-based user access ( ), Splunk Observability Cloud previews ( ), and Navigating Splunk Web ( ) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.

CVE-2026-76276
Splunk Enterprise
Oct 7, 2026
Medium4.3Splunk

Medium [CVE-2026-76275] Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search query text and job metadata for jobs that belong to other users, including job identifiers, dispatch parameters, result counts, and execution metadata, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully enforce per-user authorization before it includes job information in search job listings.

CVE-2026-76275
Splunk Enterprise
Oct 7, 2026
Medium6.5Splunk

Medium [CVE-2026-76274] Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observability Cloud

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens ( ) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.

CVE-2026-76274
Splunk Enterprise
Oct 7, 2026
Medium4.3Splunk

Medium [CVE-2026-76273] Improper Input Validation through the collect Command in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to add attacker-controlled content to system-level messages on the Splunk platform instance. The vulnerability is possible because the collect command does not validate the index name before processing the value. For more information see collect ( ), Define roles on the Splunk platform with capabilities ( ), and System endpoint descriptions ( ) in the Splunk documentation.

CVE-2026-76273
Splunk Enterprise
Oct 7, 2026
Medium4.3Splunk

Medium [CVE-2026-76272] Missing Access Control through the REST API in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. For more information see Define roles on the Splunk platform with capabilities ( ) in the Splunk documentation.

CVE-2026-76272
Splunk Enterprise
Oct 7, 2026
Medium6.5Splunk

Medium [CVE-2026-76271] Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause a denial of service against a Representational State Transfer (REST) API endpoint in the Discover Splunk Observability Cloud app. The vulnerability is possible because the app uses an inefficient regular expression to validate input submitted through the endpoint. For more information see About configuring role-based user access ( ), Splunk Observability Cloud previews ( ), and restmap.conf ( ) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.

CVE-2026-76271
Splunk Enterprise
Oct 7, 2026
Medium6.5Splunk

Medium [CVE-2026-76270] Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (REST) API, including private SPL2 module definitions belonging to other users. The vulnerability is possible because Splunk Enterprise and Splunk Cloud Platform do not parameterize user-supplied values before using them in database queries for SPL2 module filtering. For more information see Manage SPL2 modules ( ) and Module permissions ( ) in the Splunk documentation. Splunk Enterprise versions 10.2.x, 10.0.x, and 9.4.x are not affected.

CVE-2026-76270
Splunk Enterprise
Oct 7, 2026
Medium6.5Splunk

Medium [CVE-2026-76269] Improper Access Control in Search Job Retrieval through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs that belong to other users, including search query text, job metadata, results, and preview results, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully validate job ownership before returning search job information.

CVE-2026-76269
Splunk Enterprise
Oct 7, 2026
Medium4.3Splunk

Medium [CVE-2026-76267] Log Injection through the REST API in Splunk App for Splunk O11y Cloud

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could inject forged entries into the app log through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk App for Splunk O11y Cloud does not neutralize user-supplied SignalFlow content before writing it to the app log. Splunk Enterprise versions 9.4.x are not affected.

CVE-2026-76267
Splunk Enterprise
Oct 7, 2026
Medium6.5Splunk

Medium [CVE-2026-76265] Improper Access Control through REST API Endpoints in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.

CVE-2026-76265
Splunk Enterprise
Oct 7, 2026
Medium4.3Splunk

Medium [CVE-2026-76264] Improper Authorization through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.

CVE-2026-76264
Splunk Enterprise
Oct 7, 2026
Medium5.4Splunk

Medium [CVE-2026-76353] Path Traversal through Knowledge Bundle Replication in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager. This could affect system integrity and disrupt service. The vulnerability is possible because knowledge bundle delta processing does not restrict removal paths to the staging directory and the endpoint does not enforce the expected authorization boundary. For more information see Knowledge bundle replication overview ( ) in the Splunk documentation.

CVE-2026-76353
Splunk Enterprise
Aug 19, 2026
Medium6.4Splunk

Medium [CVE-2026-76349] SPL Injection through Splunk Web Form Tokens in Splunk Enterprise

In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running arbitrary Search Processing Language (SPL) commands using the permissions of the authenticated user through a crafted Splunk Web link. The SPL commands could access all relevant data. The vulnerability does not affect Splunk Enterprise 10.4 versions and above. The vulnerability is possible because Splunk Web substitutes form token values supplied through the Uniform Resource Locator (URL) into SPL searches without neutralizing them. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Token reference ( ) in the Splunk documentation.

CVE-2026-76349
Splunk Enterprise
Aug 19, 2026
Medium5.4Splunk

Medium [CVE-2026-76347] Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.

CVE-2026-76347
Splunk Enterprise
Aug 19, 2026
Medium5.4Splunk

Medium [CVE-2026-76346] Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user who views the dashboard. If the other user holds the "admin" Splunk role, the script could access all relevant data available through Splunk Web and perform actions with that user's permissions. The vulnerability is possible because Splunk Web does not limit the permitted dashboard visualization options to safe presentation settings and does not escape tooltip values before rendering them. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see About configuring role-based user access ( ) in the Splunk documentation.

CVE-2026-76346
Splunk Enterprise
Aug 19, 2026
Medium6.0Splunk

Medium [CVE-2026-76345] Remote Code Execution (RCE) through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage search head clustering could use the search head cluster member bundle Representational State Transfer (REST) API to write files to locations that the user account running Splunk Enterprise can write to, which could allow for remote code execution. Successful exploitation could result in access to all relevant data and could affect the integrity and availability of the Splunk deployment. The vulnerability does not affect Splunk Enterprise versions below 10.4. The vulnerability is possible because the search head cluster member bundle REST API does not enforce the expected authorization boundary and does not validate bundle paths before accepting bundle content. For more information see Using the REST API reference ( ), About configuring role-based user access ( ), and About distributed search ( ) in the Splunk documentation.

CVE-2026-76345
Splunk Enterprise
Aug 19, 2026

← All Splunk advisories