Splunk Enterprise vulnerabilities
212 known vulnerabilities affecting splunk/splunk_enterprise.
Total CVEs
212
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH76MEDIUM123LOW8
Vulnerabilities
Page 3 of 11
CVE-2022-43563P3HIGHCVSS 8.8≥ 8.1, < 8.1.12≥ 8.2, < 8.2.92022-11-04
CVE-2022-43563 [HIGH] CWE-20 CVE-2022-43563: In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles fi
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request w
nvd
CVE-2026-20204P3HIGHCVSS 7.1≥ 10.2, < 10.2.1≥ 10.0, < 10.0.5+2 more2026-04-15
CVE-2026-20204 [HIGH] CWE-377 CVE-2026-20204: In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform ve
In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform a Remote Code Execution (RCE) by uploading a malicio
nvd
CVE-2026-76262P3HIGHCVSS 7.5≥ 10.4, < 10.4.22026-08-19
CVE-2026-76262 [HIGH] CWE-200 CVE-2026-76262: In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus servi
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is po
nvd
CVE-2022-43565P3HIGHCVSS 8.8≥ 8.1, < 8.1.12≥ 8.2, < 8.2.92022-11-04
CVE-2022-43565 [HIGH] CWE-20 CVE-2022-43565: In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javas
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into ini
nvd
CVE-2024-29946P3HIGHCVSS 8.1≥ 9.2, < 9.2.1≥ 9.1, < 9.1.4+1 more2024-03-27
CVE-2024-29946 [HIGH] CWE-20 CVE-2024-29946: In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protec
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.
nvd
CVE-2026-76354P3HIGHCVSS 8.1≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76354 [HIGH] CWE-158 CVE-2026-76354: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API request that deletes or temporarily overwrites files writable by the user account running Splunk Enterprise p
nvd
CVE-2026-20297P3HIGHCVSS 7.2≥ 10.4, < 10.4.1≥ 10.2, < 10.2.5+3 more2026-07-15
CVE-2026-20297 [HIGH] CWE-22 CVE-2026-20297: In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Pla
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the `edit_local_apps` and `install_apps` capabilities could cause a legitimate app installation to write files outside the intended app d
nvd
CVE-2023-22939P3HIGHCVSS 8.8≥ 8.1, < 8.1.13≥ 8.2, < 8.2.10+1 more2023-02-14
CVE-2023-22939 [HIGH] CWE-20 CVE-2023-22939: In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.
nvd
CVE-2026-20296P3HIGHCVSS 8.3≥ 10.4, < 10.4.1≥ 10.2, < 10.2.5+2 more2026-07-15
CVE-2026-20296 [HIGH] CWE-352 CVE-2026-20296: In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform ve
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing Language (SPL) searches on their
nvd
CVE-2026-76322P3HIGHCVSS 8.0≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76322 [HIGH] CWE-862 CVE-2026-76322: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user"
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user" Splunk role could craft a Dashboard Studio dashboard that runs attacker-controlled Search Processing Language (SPL) for another authenticated user. The attacker-controlled SPL could access all relevant data and affect system integrity and availability. T
nvd
CVE-2021-31559P3HIGHCVSS 7.5v8.2 version(s) before 8.2.1vVersion(s) before 8.1.52022-05-06
CVE-2021-31559 [HIGH] CWE-288 CVE-2021-31559: A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splu
A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders.
nvd
CVE-2026-76255P3HIGHCVSS 7.3≥ 10.4, < 10.4.1≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76255 [HIGH] CWE-862 CVE-2026-76255: In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power" Splunk roles could trick another user into running arbitrary Search Processing Language (SPL) commands through the Data Model Editor using the permissions of the affected user. The commands could access all relevant data available to
nvd
CVE-2022-26889P3HIGHCVSS 8.8vVersion(s) before 8.1.22022-05-06
CVE-2022-26889 [HIGH] CWE-20 CVE-2022-26889: In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web pa
In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an attacker to potentially inject arbitrary content into the web page (e.g., HTML Injection, XSS) or bypass SPL safeguards for risky commands. The attack is browser-based. An attacker cannot exploit the attac
nvd
CVE-2023-40597P3HIGHCVSS 8.8≥ 8.2, < 8.2.12≥ 9.0, < 9.0.6+1 more2023-08-30
CVE-2023-40597 [HIGH] CWE-36 CVE-2023-40597: In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolu
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
nvd
CVE-2022-43568P3MEDIUMCVSS 6.1≥ 8.1, < 8.1.12≥ 8.2, < 8.2.9+1 more2022-11-04
CVE-2022-43568 [MEDIUM] CWE-79 CVE-2022-43568: In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Si
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.
nvd
CVE-2026-76259P3HIGHCVSS 7.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+3 more2026-08-19
CVE-2026-76259 [HIGH] CWE-269 CVE-2026-76259: In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all relevant data and system integrity available to the user
nvd
CVE-2023-22935P3HIGHCVSS 8.8≥ 8.1, < 8.1.13≥ 8.2, < 8.2.10+1 more2023-02-14
CVE-2023-22935 [HIGH] CWE-20 CVE-2023-22935: In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sen
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.
nvd
CVE-2024-23678P3HIGHCVSS 8.8≥ 9.0, < 9.0.8≥ 9.1, < 9.1.32024-01-22
CVE-2024-23678 [HIGH] CWE-20 CVE-2024-23678: In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctl
In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.
nvd
CVE-2021-26253P3HIGHCVSS 8.1vVersion(s) before 8.1.62022-05-06
CVE-2021-26253 [HIGH] CWE-287 CVE-2021-26253: A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the
A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and does not impact or affect a DUO product or service.
nvd
CVE-2022-32156P3HIGHCVSS 8.1fixed in 9.0.02022-06-15
CVE-2022-32156 [HIGH] CWE-295 CVE-2022-32156: In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface
In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configure TLS host name validation for the Splunk CLI https://docs.splunk.com/Documentation/Splunk/9.0.0/Security
nvd