Splunk Enterprise vulnerabilities
212 known vulnerabilities affecting splunk/splunk_enterprise.
Total CVEs
212
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH76MEDIUM123LOW8
Vulnerabilities
Page 2 of 11
CVE-2026-76317P3HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76317 [HIGH] CWE-26 CVE-2026-76317: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could move files that the user account running Splunk Enterprise can read into a lookup that the user controls. The user could then access all relevant data and affect system integrity and availability on the search head.
nvd
CVE-2026-76352P3HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76352 [HIGH] CWE-285 CVE-2026-76352: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could create or modify a scripted lookup through generic configuration endpoints and run an installed lookup script with the permissions of the user account running Splunk Enterprise, which could allow for access to all
nvd
CVE-2024-45733P3HIGHCVSS 8.8≥ 9.2, < 9.2.3≥ 9.1, < 9.1.62024-10-14
CVE-2024-45733 [HIGH] CWE-502 CVE-2024-45733: In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not
In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.
nvd
CVE-2026-76254P3HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+3 more2026-08-19
CVE-2026-76254 [HIGH] CWE-943 CVE-2026-76254: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated u
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) pipelines from Dataset Explorer with the same privileges as that user, which can allow for access to all relevant data and system integrity available to that user and af
nvd
CVE-2026-76338P3HIGHCVSS 8.1≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76338 [HIGH] CWE-287 CVE-2026-76338: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity, and disrupt service availability. The vulnerability is possible because the distributed search authenti
nvd
CVE-2022-37437P3CRITICALCVSS 9.8v9.0.02022-08-16
CVE-2022-37437 [CRITICAL] CWE-295 CVE-2022-37437: When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and an Ingest Actions Destination through Splunk Web and only applies to en
nvd
CVE-2024-36984P3HIGHCVSS 8.8≥ 9.2, < 9.2.2≥ 9.1, < 9.1.5+1 more2024-07-01
CVE-2024-36984 [HIGH] CWE-502 CVE-2024-36984: In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.
nvd
CVE-2022-43567P3HIGHCVSS 8.8≥ 8.1, < 8.1.12≥ 8.2, < 8.2.9+1 more2022-11-04
CVE-2022-43567 [HIGH] CWE-502 CVE-2022-43567: In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrar
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.
nvd
CVE-2024-36983P3HIGHCVSS 8.8≥ 9.2, < 9.2.2≥ 9.1, < 9.1.5+1 more2024-07-01
CVE-2024-36983 [HIGH] CWE-77 CVE-2024-36983: In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions belo
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From the
nvd
CVE-2023-40598P3HIGHCVSS 8.8≥ 8.2, < 8.2.12≥ 9.0, < 9.0.6+1 more2023-08-30
CVE-2023-40598 [HIGH] CWE-77 CVE-2023-40598: In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external loo
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.
nvd
CVE-2023-40595P3HIGHCVSS 8.8≥ 8.2, < 8.2.12≥ 9.0, < 9.0.6+1 more2023-08-30
CVE-2023-40595 [HIGH] CWE-502 CVE-2023-40595: In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a special
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.
nvd
CVE-2026-76316P3HIGHCVSS 8.8≥ 10.4, < 10.4.1≥ 10.2, < 10.2.5+2 more2026-08-19
CVE-2026-76316 [HIGH] CWE-943 CVE-2026-76316: In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port could store a Search Processing Language (SPL) pipeline that runs when an administrator opens the Add Data forwarder workflow. The SPL pipeline could access all relevant data, affect system integrity, and affect avail
nvd
CVE-2023-32708P3HIGHCVSS 8.8≥ 8.1, < 8.1.14≥ 8.2, < 8.2.11+1 more2023-06-01
CVE-2023-32708 [HIGH] CWE-113 CVE-2023-32708: In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions be
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.
nvd
CVE-2026-76331P3HIGHCVSS 8.1≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76331 [HIGH] CWE-943 CVE-2026-76331: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject Search Processing Language (SPL) into saved-search dispatch requests. This could allow for unauthorized access to all relevant data and affect system integrity within Splunk Enterprise. The vulnerability is
nvd
CVE-2025-20371P3HIGHCVSS 8.8≥ 10.0, < 10.0.1≥ 9.4, < 9.4.4+2 more2025-10-01
CVE-2025-20371 [HIGH] CWE-918 CVE-2025-20371: In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versio
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an authenticated high-privileged user.
nvd
CVE-2026-76344P3HIGHCVSS 7.7≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76344 [HIGH] CWE-27 CVE-2026-76344: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Representational State Transfer (REST) API endpoint and affect system integrity on the host. The vulnerabili
nvd
CVE-2026-20252P3HIGHCVSS 7.6≥ 10.2, < 10.2.4≥ 10.0, < 10.0.7+2 more2026-06-10
CVE-2026-20252 [HIGH] CWE-918 CVE-2026-20252: In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could send server-side requests to arbitrary internal destinations through the Dashboard S
nvd
CVE-2026-76355P3HIGHCVSS 7.5≥ 10.4, < 10.4.22026-08-19
CVE-2026-76355 [HIGH] CWE-306 CVE-2026-76355: In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the informat
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer (REST) API endpoint when Edge Processor is turned on. The vulnerability does not affect versions prior to 10.4. The vulnerability exists because the Edge P
nvd
CVE-2026-76321P3HIGHCVSS 7.3≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76321 [HIGH] CWE-77 CVE-2026-76321: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could inject arbitrary Search Processing Language (SPL) into requests that search for events near a selected event. This could allow for unauthorized search execution. The vulnerability is possible because Splunk Web does not consistently escape caller-suppl
nvd
CVE-2026-20163P3HIGHCVSS 7.2≥ 10.0, < 10.0.4≥ 9.4, < 9.4.9+1 more2026-03-11
CVE-2026-20163 [HIGH] CWE-77 CVE-2026-20163: In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform ver
In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that contains the high-privilege capability `edit_cmd` could execute arbitrary shell commands using the `unarchive_cmd` parameter for the `/splunkd/__upload/in
nvd