Skip to content
VulniPulse

Splunk ES / ITSI / SOAR Vulnerabilities & Security Advisories

38 advisories tracked · Splunk (prodsec@splunk.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Splunk advisory that VulniPulse classified as ES / ITSI / SOAR, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 8 high, 27 medium, 3 low.

Android app · Google Play

Monitor Splunk CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

Splunk (prodsec@splunk.com CNA) via NVD

Splunk is its own CVE Numbering Authority. VulniPulse ingests Splunk's CVEs from the NVD CNA feed (prodsec@splunk.com), each linking to its SVD-YYYY-NNNN advisory on advisory.splunk.com. Covers Splunk Enterprise, Splunk Cloud Platform, the Universal Forwarder, IT Service Intelligence (ITSI), SOAR, Enterprise Security and Splunk apps/add-ons — the SIEM at the centre of most SOCs, so a security-team audience that patches on advisory day.

Latest Splunk ES / ITSI / SOAR advisories

Medium6.5Splunk

Medium [CVE-2026-76363] Structured Query Language Injection through the REST API in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database and create, read, update, or delete all data in the database. The vulnerability is possible because Splunk SOAR playbook automation data APIs incorporate user-supplied input into database queries without proper neutralization. For more information see Manage roles and permissions in Splunk SOAR Cloud ( ) in the Splunk documentation.

CVE-2026-76363
ES / ITSI / SOAR
Aug 19, 2026
Medium4.3Splunk

Medium [CVE-2026-76360] Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing authorization check, where the endpoint does not verify that the caller holds a role permitted to view system health and cluster state. For more information see Manage roles and permissions in Splunk SOAR (On-premises) ( ) and Monitor the health of your Splunk SOAR (On-premises) system ( ) in the Splunk documentation.

CVE-2026-76360
ES / ITSI / SOAR
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76359] Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended installation directory. The vulnerability is possible because the Universal Forwarder credentials-package extraction workflow does not verify that each archive member remains within the intended destination before extraction. For more information see Manage roles and permissions in Splunk SOAR (On-premises) ( ) and Configure forwarders to send SOAR data to your Splunk deployment ( ) in the Splunk documentation.

CVE-2026-76359
ES / ITSI / SOAR
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76358] Path Traversal through App Installation Tar Extraction in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the intended temporary directory. The vulnerability is a path traversal in the archive extraction routine, which does not validate that extracted file paths stay within the intended destination directory. For more information see Manage roles and permissions in Splunk SOAR (On-premises) ( ) and Add and configure apps and assets to provide actions in Splunk SOAR (On-premises) ( ) in the Splunk documentation.

CVE-2026-76358
ES / ITSI / SOAR
Aug 19, 2026
Medium6.4Splunk

Medium [CVE-2025-22621] In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the…

In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roles.

CVE-2025-22621
ES / ITSI / SOAR
Jan 7, 2025
Medium6.5Splunk

Medium [CVE-2024-22165] In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations manager until it is deleted. The vulnerability requires an authenticated session and access to create an Investigation. It only affects the availability of the Investigations manager, but without the manager, the Investigations functionality becomes unusable for most users.

CVE-2024-22165
Splunk EnterpriseES / ITSI / SOAR
Jan 9, 2024
Medium4.3Splunk

Medium [CVE-2024-22164] In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.

CVE-2024-22164
Splunk EnterpriseES / ITSI / SOAR
Jan 9, 2024

← All Splunk advisories