Skip to content
VulniPulse

Splunk Security Advisories & CVEs

97 advisories tracked · Splunk (prodsec@splunk.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Splunk CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Splunk device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Splunk's recent advisories.

Official source

Splunk (prodsec@splunk.com CNA) via NVD

Splunk is its own CVE Numbering Authority. VulniPulse ingests Splunk's CVEs from the NVD CNA feed (prodsec@splunk.com), each linking to its SVD-YYYY-NNNN advisory on advisory.splunk.com. Covers Splunk Enterprise, Splunk Cloud Platform, the Universal Forwarder, IT Service Intelligence (ITSI), SOAR, Enterprise Security and Splunk apps/add-ons — the SIEM at the centre of most SOCs, so a security-team audience that patches on advisory day.

Latest Splunk advisories

High7.4Splunk

High [CVE-2026-76403] Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because the Kerberos authentication path does not apply the configured certificate validation options when it builds the HTTP client. For more information see Install Splunk Connect for Kafka ( ), Security configurations for Splunk Connect for Kafka ( ), and Set up and use HTTP Event Collector with configuration files ( ) in the Splunk documentation.

CVE-2026-76403
Unclassified
Aug 19, 2026
High8.2Splunk

High [CVE-2026-76402] Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the connector to send authentication credentials to an attacker-controlled server, allowing for exposure of credentials that compromise all relevant data sent through the connector and limited alteration of event delivery. The vulnerability is possible because HTTP Event Collector endpoint validation does not require secure transport by default. For more information see Install Splunk Connect for Kafka ( ), Data ingestion parameters for Splunk Connect for Kafka ( ), and Set up and use HTTP Event Collector with configuration files ( ) in the Splunk documentation.

CVE-2026-76402
Unclassified
Aug 19, 2026
High8.1Splunk

High [CVE-2026-76399] Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.

CVE-2026-76399
Unclassified
Aug 19, 2026
High8.1Splunk

High [CVE-2026-76397] Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants ( ) in the Splunk documentation.

CVE-2026-76397
Unclassified
Aug 19, 2026
High7.5Splunk

High [CVE-2026-76396] Improper Access Control through Scheduled Searches in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit ( ) in the Splunk documentation.

CVE-2026-76396
Unclassified
Aug 19, 2026
High8.8Splunk

High [CVE-2026-76395] Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Troubleshoot the Splunk Machine Learning Toolkit ( ) in the Splunk documentation.

CVE-2026-76395
Unclassified
Aug 19, 2026
High8.3Splunk

High [CVE-2026-76394] Missing Authorization in Container and Connection Management through the REST API in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because multiple REST API handlers in Splunk AI Toolkit do not enforce authorization checks. For more information see Troubleshoot the Splunk Machine Learning Toolkit ( ) in the Splunk documentation.

CVE-2026-76394
Unclassified
Aug 19, 2026
High8.3Splunk

High [CVE-2026-76391] Improper Privilege Management through Agent Run History in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege management is possible because the Agent Run History handler replaces the calling user session key with a system authentication token before it performs search operations. For more information see AI Toolkit Agent Launchpad ( ) in the Splunk documentation.

CVE-2026-76391
Unclassified
Aug 19, 2026
High8.8Splunk

High [CVE-2026-76389] Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for Enterprise Security Cloud

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to an attacker-controlled server. The request could expose tokens that compromise all relevant data and system integrity in the Splunk instance. The vulnerability is possible because the Talos intelligence enrichment REST endpoint accepts the destination for authenticated Splunk management requests from request data. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security ( ) in the Splunk documentation.

CVE-2026-76389
ES / ITSI / SOAR
Aug 19, 2026
High8.1Splunk

High [CVE-2026-76388] Privilege Escalation through Search Macro Permissions in Splunk Enterprise Security

In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all relevant data and system integrity through those searches. The vulnerability is possible because the UEBA app metadata grants analyst roles write access to search macros that should be writable only by administrator roles. For more information see Users and roles for Splunk Enterprise Security ( ) and Roles and knowledge objects in UEBA for Splunk Enterprise Security ( ) in the Splunk documentation.

CVE-2026-76388
Splunk EnterpriseES / ITSI / SOAR
Aug 19, 2026
High8.1Splunk

High [CVE-2026-76387] SPL Injection through the REST API in Splunk Enterprise Security

In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the scheduled searches that run for that user. The vulnerability is possible because the Analyst Queue search filter handling does not validate filter field names before the fields are included in SPL searches. For more information see Users and roles for Splunk Enterprise Security ( ), Manage analyst workflows using the analyst queue in Splunk Enterprise Security ( ), and Overview of Mission Control in Splunk Enterprise Security ( ) in the Splunk documentation.

CVE-2026-76387
Splunk EnterpriseES / ITSI / SOAR
Aug 19, 2026
High7.4Splunk

High [CVE-2026-76362] Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR

In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server could access or modify all relevant data exchanged through that credential manager. The vulnerability is possible because the CyberArk REST client does not verify server certificates by default. The attack requires the attacker to have network-path interception capability between Splunk SOAR and the configured CyberArk REST server. For more information see Manage your organization's credentials with a password vault ( ) in the Splunk documentation.

CVE-2026-76362
ES / ITSI / SOAR
Aug 19, 2026
High7.6Splunk

High [CVE-2026-76357] Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role for the request and does not restrict the user-supplied file path to the intended temporary directory. For more information see Manage roles and permissions in Splunk SOAR (On-premises) ( ) and Splunk SOAR (On-premises) security information ( ) in the Splunk documentation.

CVE-2026-76357
ES / ITSI / SOAR
Aug 19, 2026
High8.1Splunk

High [CVE-2026-76356] Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation Broker trusts a client-supplied source IP address header as proof that the request originates from the local system. Successful exploitation can expose all relevant data, affect system integrity, and disrupt service availability. For more information see About Splunk SOAR Automation Broker ( ) in the Splunk documentation.

CVE-2026-76356
ES / ITSI / SOAR
Aug 19, 2026
High7.5Splunk

High [CVE-2026-76355] Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk Enterprise

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer (REST) API endpoint when Edge Processor is turned on. The vulnerability does not affect versions prior to 10.4. The vulnerability exists because the Edge Processor service endpoint lacks authentication controls. For more information see System architecture of the Edge Processor solution ( ) in the Splunk documentation.

CVE-2026-76355
Splunk Enterprise
Aug 19, 2026
High8.1Splunk

High [CVE-2026-76354] Path Traversal through Search Head Clustering in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API request that deletes or temporarily overwrites files writable by the user account running Splunk Enterprise processes on a non-captain search head cluster member. The vulnerability is possible because Search Head Clustering bundle replication does not validate the name of a replicated bundle file or neutralize NUL bytes before constructing the member bundle path. For more information see About search head clustering ( ), Define roles on the Splunk platform with capabilities ( ), and Secure Splunk Enterprise service accounts ( ) in the Splunk documentation.

CVE-2026-76354
Splunk Enterprise
Aug 19, 2026
High8.8Splunk

High [CVE-2026-76352] Improper Authorization through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could create or modify a scripted lookup through generic configuration endpoints and run an installed lookup script with the permissions of the user account running Splunk Enterprise, which could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the generic transforms configuration endpoints do not enforce the capabilities required to create or edit external lookup definitions. For more information see Define roles on the Splunk platform with capabilities ( ) and limits.conf ( ) in the Splunk documentation.

CVE-2026-76352
Splunk Enterprise
Aug 19, 2026
High8.8Splunk

High [CVE-2026-76351] Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise Representational State Transfer (REST) API using a system-level session token and modify the Splunk platform configuration. The user could then obtain a session token without a password and use it to access all relevant data and affect system integrity. The vulnerability is possible because Splunk Secure Gateway does not validate decoded report notification identifiers before using them to construct requests to the Splunk Enterprise REST API.

CVE-2026-76351
Splunk Enterprise
Aug 19, 2026
High8.8Splunk

High [CVE-2026-76350] Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure Portable Document Format (PDF) attachments in the email alert action workflow. When the email alert action runs, it could execute arbitrary Search Processing Language (SPL) commands with system-level privileges, expose all relevant data, and affect system integrity and availability on the search head. The vulnerability is possible because the search scheduler passes a system-level authentication context rather than the action owner context to the email alert action when it renders PDF attachments. For more information see alert_actions.conf ( ) in the Splunk documentation.

CVE-2026-76350
Splunk Enterprise
Aug 19, 2026
High7.7Splunk

High [CVE-2026-76344] Path Traversal through the Search Dispatch REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Representational State Transfer (REST) API endpoint and affect system integrity on the host. The vulnerability is possible because Splunk Enterprise does not validate the search identifier before using it to create a dispatch directory. For more information see About configuring role-based user access ( ) in the Splunk documentation.

CVE-2026-76344
Splunk Enterprise
Aug 19, 2026

← All vendors