Skip to content
VulniPulse

Splunk Security Advisories & CVEs

220 advisories tracked · Splunk (prodsec@splunk.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Splunk CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Splunk device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Splunk's recent advisories.

Official source

Splunk (prodsec@splunk.com CNA) via NVD

Splunk is its own CVE Numbering Authority. VulniPulse ingests Splunk's CVEs from the NVD CNA feed (prodsec@splunk.com), each linking to its SVD-YYYY-NNNN advisory on advisory.splunk.com. Covers Splunk Enterprise, Splunk Cloud Platform, the Universal Forwarder, IT Service Intelligence (ITSI), SOAR, Enterprise Security and Splunk apps/add-ons — the SIEM at the centre of most SOCs, so a security-team audience that patches on advisory day.

Latest Splunk advisories

Medium4.3Splunk

Medium [CVE-2026-76377] Information Disclosure through Action Parameters in Azure AD Graph app for Splunk SOAR

In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR ( ).

CVE-2026-76377
ES / ITSI / SOAR
Aug 19, 2026
Medium4.3Splunk

Medium [CVE-2026-76376] Information Disclosure through Action Parameters in AWS IAM app for Splunk SOAR

In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive AWS credentials by invoking an action that accepts the credentials parameter, because the parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR ( ).

CVE-2026-76376
ES / ITSI / SOAR
Aug 19, 2026
Medium5.0Splunk

Medium [CVE-2026-76375] Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAR

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an action in Splunk SOAR ( ).

CVE-2026-76375
ES / ITSI / SOAR
Aug 19, 2026
Medium4.3Splunk

Medium [CVE-2026-76374] Information Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOAR

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR ( ).

CVE-2026-76374
ES / ITSI / SOAR
Aug 19, 2026
Medium5.4Splunk

Medium [CVE-2026-76373] Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read sensitive attributes from arbitrary directory objects, and redirect account modification actions to unintended objects. For more information see Run an action in Splunk SOAR ( ).

CVE-2026-76373
ES / ITSI / SOAR
Aug 19, 2026
Medium4.3Splunk

Medium [CVE-2026-76370] Information Disclosure through the REST API in Splunk SOAR

In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names and identifiers of tenants that fall outside the role scope for that user. The vulnerability is possible because Splunk SOAR does not enforce role-based tenant restrictions when it returns tenant information through the REST API in deployments with multi-tenancy turned on. For more information see REST Roles and Permissions ( ) and Configure multiple tenants on your Splunk SOAR (On-premises) instance ( ) in the Splunk documentation.

CVE-2026-76370
ES / ITSI / SOAR
Aug 19, 2026
Medium4.0Splunk

Medium [CVE-2026-76367] Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a note and run it in the browser of another user when that user opens the note. The stored Cross-Site Scripting (XSS) vulnerability is possible because Splunk SOAR can treat existing note content as Hypertext Markup Language (HTML) without sanitizing that content when the note format changes. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "Incident Commander" Splunk SOAR role should not be able to exploit the vulnerability at will. For more information see Manage roles and permissions in Splunk SOAR (Cloud) ( ) in the Splunk documentation.

CVE-2026-76367
ES / ITSI / SOAR
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76366] Information Disclosure through the REST API in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible because Splunk SOAR does not block REST API filters from matching values that responses otherwise hide. For more information see REST Run Playbook ( ) in the Splunk documentation.

CVE-2026-76366
ES / ITSI / SOAR
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76365] Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom list retrieval in a playbook, allowing for create, read, update, and delete operations on all relevant data stored in the Splunk SOAR database. The SQL injection is possible because Splunk SOAR builds the custom list database lookup with the supplied list name instead of a bound SQL value. For more information see Manage roles and permissions in Splunk SOAR ( ) and Create custom lists for use in Splunk SOAR playbook comparisons ( ) in the Splunk documentation.

CVE-2026-76365
ES / ITSI / SOAR
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76364] Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom function results, allowing for reading all relevant data stored in the Splunk SOAR database and affecting system integrity. The SQL injection is possible because Splunk SOAR builds the database lookup with the supplied name instead of a bound SQL value. For more information see Manage roles and permissions in Splunk SOAR (Cloud) ( ) in the Splunk documentation.

CVE-2026-76364
ES / ITSI / SOAR
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76363] Structured Query Language Injection through the REST API in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database and create, read, update, or delete all data in the database. The vulnerability is possible because Splunk SOAR playbook automation data APIs incorporate user-supplied input into database queries without proper neutralization. For more information see Manage roles and permissions in Splunk SOAR Cloud ( ) in the Splunk documentation.

CVE-2026-76363
ES / ITSI / SOAR
Aug 19, 2026
Medium4.3Splunk

Medium [CVE-2026-76360] Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing authorization check, where the endpoint does not verify that the caller holds a role permitted to view system health and cluster state. For more information see Manage roles and permissions in Splunk SOAR (On-premises) ( ) and Monitor the health of your Splunk SOAR (On-premises) system ( ) in the Splunk documentation.

CVE-2026-76360
ES / ITSI / SOAR
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76359] Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended installation directory. The vulnerability is possible because the Universal Forwarder credentials-package extraction workflow does not verify that each archive member remains within the intended destination before extraction. For more information see Manage roles and permissions in Splunk SOAR (On-premises) ( ) and Configure forwarders to send SOAR data to your Splunk deployment ( ) in the Splunk documentation.

CVE-2026-76359
ES / ITSI / SOAR
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76358] Path Traversal through App Installation Tar Extraction in Splunk SOAR

In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the intended temporary directory. The vulnerability is a path traversal in the archive extraction routine, which does not validate that extracted file paths stay within the intended destination directory. For more information see Manage roles and permissions in Splunk SOAR (On-premises) ( ) and Add and configure apps and assets to provide actions in Splunk SOAR (On-premises) ( ) in the Splunk documentation.

CVE-2026-76358
ES / ITSI / SOAR
Aug 19, 2026
Medium5.4Splunk

Medium [CVE-2026-76353] Path Traversal through Knowledge Bundle Replication in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager. This could affect system integrity and disrupt service. The vulnerability is possible because knowledge bundle delta processing does not restrict removal paths to the staging directory and the endpoint does not enforce the expected authorization boundary. For more information see Knowledge bundle replication overview ( ) in the Splunk documentation.

CVE-2026-76353
Splunk Enterprise
Aug 19, 2026
Medium6.4Splunk

Medium [CVE-2026-76349] SPL Injection through Splunk Web Form Tokens in Splunk Enterprise

In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running arbitrary Search Processing Language (SPL) commands using the permissions of the authenticated user through a crafted Splunk Web link. The SPL commands could access all relevant data. The vulnerability does not affect Splunk Enterprise 10.4 versions and above. The vulnerability is possible because Splunk Web substitutes form token values supplied through the Uniform Resource Locator (URL) into SPL searches without neutralizing them. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Token reference ( ) in the Splunk documentation.

CVE-2026-76349
Splunk Enterprise
Aug 19, 2026
Medium5.4Splunk

Medium [CVE-2026-76347] Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.

CVE-2026-76347
Splunk Enterprise
Aug 19, 2026
Medium5.4Splunk

Medium [CVE-2026-76346] Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user who views the dashboard. If the other user holds the "admin" Splunk role, the script could access all relevant data available through Splunk Web and perform actions with that user's permissions. The vulnerability is possible because Splunk Web does not limit the permitted dashboard visualization options to safe presentation settings and does not escape tooltip values before rendering them. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see About configuring role-based user access ( ) in the Splunk documentation.

CVE-2026-76346
Splunk Enterprise
Aug 19, 2026
Medium6.0Splunk

Medium [CVE-2026-76345] Remote Code Execution (RCE) through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage search head clustering could use the search head cluster member bundle Representational State Transfer (REST) API to write files to locations that the user account running Splunk Enterprise can write to, which could allow for remote code execution. Successful exploitation could result in access to all relevant data and could affect the integrity and availability of the Splunk deployment. The vulnerability does not affect Splunk Enterprise versions below 10.4. The vulnerability is possible because the search head cluster member bundle REST API does not enforce the expected authorization boundary and does not validate bundle paths before accepting bundle content. For more information see Using the REST API reference ( ), About configuring role-based user access ( ), and About distributed search ( ) in the Splunk documentation.

CVE-2026-76345
Splunk Enterprise
Aug 19, 2026
Medium6.5Splunk

Medium [CVE-2026-76343] Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint, allowing for access to substantially all data stored by Data Orchestration, including jobs owned by other users and stored connection credentials. The vulnerability is possible because Data Orchestration builds a database query from user-controlled job filter values without using parameterized queries. For more information see About configuring role-based user access ( ) in the Splunk documentation.

CVE-2026-76343
Splunk Enterprise
Aug 19, 2026

← All vendors