Splunk Enterprise vulnerabilities
212 known vulnerabilities affecting splunk/splunk_enterprise.
Total CVEs
212
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH76MEDIUM123LOW8
Vulnerabilities
Page 5 of 11
CVE-2025-20387P3MEDIUMCVSS 6.5≥ 10.0, < 10.0.2≥ 9.4, < 9.4.6+2 more2025-12-03
CVE-2025-20387 [MEDIUM] CWE-732 CVE-2025-20387: In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new ins
In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.
nvd
CVE-2026-76260P3MEDIUMCVSS 6.5≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76260 [MEDIUM] CWE-732 CVE-2026-76260: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the rest_properties_get capability could read encrypted stored credentials through the Representational State Transfer (REST) API. Successful exploitation can expose relevant data protected by the stored credentials. The incorrect permission assignm
nvd
CVE-2026-76257P3MEDIUMCVSS 6.5≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76257 [MEDIUM] CWE-862 CVE-2026-76257: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Gateway administration privileges could access Mobile Device Management signing secrets that compromise
nvd
CVE-2026-76261P3MEDIUMCVSS 6.5≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76261 [MEDIUM] CWE-732 CVE-2026-76261: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, which are secrets that compromise affected Spacebridge private-key material stored in the app collect
nvd
CVE-2026-76327P3MEDIUMCVSS 6.4≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76327 [MEDIUM] CWE-943 CVE-2026-76327: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a crafted Splunk Web Uniform Resource Locator (URL). The resulting dashboard searches could run arbitrary
nvd
CVE-2026-76345P3MEDIUMCVSS 6.0≥ 10.4, < 10.4.22026-08-19
CVE-2026-76345 [MEDIUM] CWE-284 CVE-2026-76345: In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage
In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage search head clustering could use the search head cluster member bundle Representational State Transfer (REST) API to write files to locations that the user account running Splunk Enterprise can write to, which could allow for remote code execution. S
nvd
CVE-2023-22941P3HIGHCVSS 7.5≥ 8.1, < 8.1.13≥ 8.2, < 8.2.10+1 more2023-02-14
CVE-2023-22941 [HIGH] CWE-248 CVE-2023-22941: In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).
nvd
CVE-2026-76330P3HIGHCVSS 7.1≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76330 [HIGH] CWE-20 CVE-2026-76330: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL
nvd
CVE-2026-20202P3MEDIUMCVSS 6.6≥ 10.2, < 10.2.2≥ 10.0, < 10.0.5+2 more2026-04-15
CVE-2026-20202 [MEDIUM] CWE-176 CVE-2026-20202: In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform ve
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a specially crafted username that includes a null byte or a
nvd
CVE-2026-20239P3MEDIUMCVSS 6.5≥ 10.2, < 10.2.2≥ 10.0, < 10.0.52026-05-20
CVE-2026-20239 [MEDIUM] CWE-532 CVE-2026-20239: In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.
nvd
CVE-2024-36987P3MEDIUMCVSS 6.5≥ 9.2, < 9.2.2≥ 9.1, < 9.1.5+1 more2024-07-01
CVE-2024-36987 [MEDIUM] CWE-434 CVE-2024-36987: In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions belo
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the admin or power Splunk roles could upload a file with an arbitrary extension using the indexing/preview REST endpoint.
nvd
CVE-2024-45741P3MEDIUMCVSS 5.4≥ 9.2, < 9.2.3≥ 9.1, < 9.1.62024-10-14
CVE-2024-45741 [MEDIUM] CWE-79 CVE-2024-45741: In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.240
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom configuration file that the "api.uri" parameter from the "/manager/search/apps/local" endpoint in Spl
nvd
CVE-2021-42743P3HIGHCVSS 7.8v8.1 version(s) before 8.1.12022-05-06
CVE-2021-42743 [HIGH] CWE-427 CVE-2021-42743: A misconfiguration in the node default path allows for local privilege escalation from a lower privi
A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.
nvd
CVE-2023-40593P3HIGHCVSS 7.5≥ 8.2, < 8.2.12≥ 9.0, < 9.0.62023-08-30
CVE-2023-40593 [HIGH] CWE-400 CVE-2023-40593: In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed se
In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.
nvd
CVE-2024-36982P3HIGHCVSS 7.5≥ 9.2, < 9.2.2≥ 9.1, < 9.1.5+1 more2024-07-01
CVE-2024-36982 [HIGH] CWE-476 CVE-2024-36982: In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions belo
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.
nvd
CVE-2026-76333P3HIGHCVSS 7.1≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76333 [HIGH] CWE-79 CVE-2026-76333: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action with a crafted Uniform Resource Locator (URL). When another authenticated user selects the stored action from Event Actions and selects Continue, attacker-controlled JavaScript runs in the brows
nvd
CVE-2026-76328P3MEDIUMCVSS 6.7≥ 10.4, < 10.4.1≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76328 [MEDIUM] CWE-77 CVE-2026-76328: In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a dashboard. When another authenticated user exports the dashboard as a Portable Document Format (PDF) file, Splunk Enterprise runs the injected SPL using the permissions
nvd
CVE-2025-20230P3MEDIUMCVSS 6.5≥ 9.4, < 9.4.1≥ 9.3, < 9.3.3+2 more2025-03-26
CVE-2025-20230 [MEDIUM] CWE-284 CVE-2025-20230: In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could edit and delete other user data in App Key Value Store (KVStore) collections that the Splunk Secure Gate
nvd
CVE-2026-20141P3MEDIUMCVSS 6.5≥ 10.0, < 10.0.3≥ 9.4, < 9.4.8+1 more2026-02-18
CVE-2026-20141 [MEDIUM] CWE-200 CVE-2026-20141: In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does
In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access the Splunk Monitoring Console App endpoints due to an improper access control. This could lead to a sensitive information disclosure.The Monitoring Console app is a bundled app that comes with Splunk Ente
nvd
CVE-2026-76349P3MEDIUMCVSS 6.4≥ 10.2, < 10.2.6≥ 10.0, < 10.0.9+1 more2026-08-19
CVE-2026-76349 [MEDIUM] CWE-943 CVE-2026-76349: In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick
In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running arbitrary Search Processing Language (SPL) commands using the permissions of the authenticated user through a crafted Splunk Web link. The SPL commands could access all relevant data. The vulnerability does not affect
nvd