Splunk vulnerabilities
264 known vulnerabilities affecting splunk/splunk.
Total CVEs
264
CISA KEV
2
actively exploited
Public exploits
13
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH87MEDIUM154LOW11
Vulnerabilities
Page 1 of 14
CVE-2026-20253P1CRITICALCVSS 9.8KEVPoC≥ 10.0.0, < 10.0.7≥ 10.2.0, < 10.2.42026-06-10
CVE-2026-20253 [CRITICAL] CWE-306 CVE-2026-20253: In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated use
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file oper
nvd
CVE-2014-0160P1HIGHCVSS 7.5KEVPoC≥ 6.0.0, < 6.0.32014-04-07
CVE-2014-0160 [HIGH] CWE-125 CVE-2014-0160: The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heart
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed b
nvd
CVE-2018-11409P2MEDIUMCVSS 5.3ExploitedPoC≤ 7.0.12018-06-08
CVE-2018-11409 [MEDIUM] CWE-200 CVE-2018-11409: Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-in
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.
nvd
CVE-2024-36991P1HIGHCVSS 7.5ExploitedPoC≥ 9.0.0, < 9.0.10≥ 9.1.0, < 9.1.5+1 more2024-07-01
CVE-2024-36991 [HIGH] CWE-35 CVE-2024-36991: In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
nvd
CVE-2023-46214P1HIGHCVSS 8.8PoC≥ 9.0.0, < 9.0.7≥ 9.1.0, < 9.1.22023-11-16
CVE-2023-46214 [HIGH] CWE-91 CVE-2023-46214: In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize exte
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.
nvd
CVE-2023-32707P2HIGHCVSS 8.8PoC≥ 8.1.0, < 8.1.14≥ 8.2.0, < 8.2.11+1 more2023-06-01
CVE-2023-32707 [HIGH] CWE-285 CVE-2023-32707: In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below ve
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
nvd
CVE-2024-36985P2HIGHCVSS 8.8PoC≥ 9.0.0, < 9.0.10≥ 9.1.0, < 9.1.5+1 more2024-07-01
CVE-2024-36985 [HIGH] CWE-687 CVE-2024-36985: In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not ho
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.
nvd
CVE-2022-43571P2HIGHCVSS 8.8PoC≥ 8.1.0, < 8.1.12≥ 8.2.0, < 8.2.9+1 more2022-11-03
CVE-2022-43571 [HIGH] CWE-94 CVE-2022-43571: In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbi
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
nvd
CVE-2011-4644P2CRITICALCVSS 9.3PoC≤ 4.2.5v2.1+63 more2012-01-03
CVE-2011-4644 [CRITICAL] CWE-287 CVE-2011-4644: Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functiona
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-console session that leverages the ability to create crafted data sources, or (2) execute managem
nvd
CVE-2026-20251P2HIGHCVSS 8.8≥ 9.3.0, < 9.3.13≥ 9.4.0, < 9.4.12+2 more2026-06-10
CVE-2026-20251 [HIGH] CWE-502 CVE-2026-20251: In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versio
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution
nvd
CVE-2023-32714P2HIGHCVSS 8.1≥ 8.1.0, < 8.1.14≥ 8.2.0, < 8.2.11+1 more2023-06-01
CVE-2023-32714 [HIGH] CWE-35 CVE-2023-32714: In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a sp
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.
nvd
CVE-2011-4642P3MEDIUMCVSS 4.6PoCv4.2v4.2.1+3 more2012-01-03
CVE-2011-4642 [MEDIUM] CWE-352 CVE-2011-4642: mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy comm
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a request to the search application, as demonstrated by a cross-site request forgery (CSRF) attack, aka SPL-45172.
nvd
CVE-2026-76314P2HIGHCVSS 8.8≥ 9.4.0, < 9.4.14≥ 10.0.0, < 10.0.9+2 more2026-08-19
CVE-2026-76314 [HIGH] CWE-94 CVE-2026-76314: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect system integrity and availability. The vulnerability is pos
nvd
CVE-2025-20229P2HIGHCVSS 8.0≥ 9.1.0, < 9.1.8≥ 9.2.0, < 9.2.5+2 more2025-03-26
CVE-2025-20229 [HIGH] CWE-284 CVE-2025-20229: In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions bel
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) through a file upload to the "$SPLUNK_HOME/var/run/splunk/apptemp" dire
nvd
CVE-2026-76310P2CRITICALCVSS 9.4≥ 9.4.0, < 9.4.14≥ 10.0.0, < 10.0.9+2 more2026-08-19
CVE-2026-76310 [CRITICAL] CWE-284 CVE-2026-76310: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative
nvd
CVE-2026-76313P2HIGHCVSS 8.8≥ 9.4.0, < 9.4.14≥ 10.0.0, < 10.0.9+2 more2026-08-19
CVE-2026-76313 [HIGH] CWE-284 CVE-2026-76313: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availab
nvd
CVE-2026-76315P2HIGHCVSS 8.8≥ 9.4.0, < 9.4.14≥ 10.0.0, < 10.0.9+2 more2026-08-19
CVE-2026-76315 [HIGH] CWE-94 CVE-2026-76315: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute arbitrary code on the Splunk platform instance through Splunk Web Manager Configuration. The user could then access all relevant data and affect system integrity and availability on the Splunk platform insta
nvd
CVE-2026-76319P2HIGHCVSS 8.8≥ 9.4.0, < 9.4.14≥ 10.0.0, < 10.0.9+2 more2026-08-19
CVE-2026-76319 [HIGH] CWE-862 CVE-2026-76319: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that d
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution through Federated Search bundle selection. This could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because th
nvd
CVE-2026-76351P2HIGHCVSS 8.8≥ 9.4.0, < 9.4.14≥ 10.0.0, < 10.0.9+2 more2026-08-19
CVE-2026-76351 [HIGH] CWE-918 CVE-2026-76351: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise Representational State Transfer (R
nvd
CVE-2022-32158P2CRITICALCVSS 10.0fixed in 9.02022-06-15
CVE-2022-32158 [CRITICAL] CWE-284 CVE-2022-32158: Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deplo
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to
nvd
1 / 14Next →