cbcvebase.

Splunk Enterprise vulnerabilities

212 known vulnerabilities affecting splunk/splunk_enterprise.

Total CVEs
212
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH76MEDIUM123LOW8

Vulnerabilities

Page 7 of 11
CVE-2026-20137P4MEDIUMCVSS 5.7≥ 10.2, < 10.2.0≥ 10.0, < 10.0.3+3 more2026-02-18
CVE-2026-20137 [MEDIUM] CWE-200 CVE-2026-20137: In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platfo In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the "admin" or "power" Splunk roles could bypass the SPL safeguards for risky commands when they create a Data Model that contains an i
nvd
CVE-2023-32716P4MEDIUMCVSS 6.5≥ 8.1, < 8.1.14≥ 8.2, < 8.2.11+1 more2023-06-01
CVE-2023-32716 [MEDIUM] CWE-754 CVE-2023-32716: In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions be In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulnerability in the {{dump}} SPL command to cause a denial of service by crashing the Splunk daemon.
nvd
CVE-2023-32706P4MEDIUMCVSS 6.5≥ 8.1, < 8.1.14≥ 8.2, < 8.2.11+1 more2023-06-01
CVE-2023-32706 [MEDIUM] CWE-611 CVE-2023-32706: On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon.
nvd
CVE-2024-23675P4MEDIUMCVSS 6.5≥ 9.0, < 9.0.8≥ 9.1, < 9.1.32024-01-22
CVE-2024-23675 [MEDIUM] CWE-284 CVE-2024-23675: In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperl In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.
nvd
CVE-2025-20232P4MEDIUMCVSS 5.7≥ 9.3, < 9.3.3≥ 9.2, < 9.2.5+1 more2025-03-26
CVE-2025-20232 [MEDIUM] CWE-200 CVE-2025-20232: In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.2312.208 and 9.1.2308.212, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to b
nvd
CVE-2025-20226P4MEDIUMCVSS 5.7≥ 9.4, < 9.4.1≥ 9.3, < 9.3.3+2 more2025-03-26
CVE-2025-20226 [MEDIUM] CWE-200 CVE-2025-20226: In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform version In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.111, and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safegu
nvd
CVE-2024-53244P4MEDIUMCVSS 5.7≥ 9.3, < 9.3.2≥ 9.2, < 9.2.4+1 more2024-12-10
CVE-2024-53244 [MEDIUM] CWE-200 CVE-2024-53244: In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards fo
nvd
CVE-2026-20256P4MEDIUMCVSS 5.7≥ 10.2, < 10.2.4≥ 10.0, < 10.0.7+2 more2026-06-10
CVE-2026-20256 [MEDIUM] CWE-20 CVE-2026-20256: In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could cause data exfiltration through classic dashboards by redirecting a victim to an external site u
nvd
CVE-2026-20257P4MEDIUMCVSS 5.7≥ 10.2, < 10.2.4≥ 10.0, < 10.0.7+2 more2026-06-10
CVE-2026-20257 [MEDIUM] CWE-20 CVE-2026-20257: In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a classic dashboard that exfiltrates sensitive data from the browser of a higher-privilege
nvd
CVE-2026-76326P4MEDIUMCVSS 5.7≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76326 [MEDIUM] CWE-79 CVE-2026-76326: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could store a dashboard view that runs JavaScript in the browser of another user who opens it and hovers over a sparkline table cell, allowing for access to all relevant data and system integrity available to that user.
nvd
CVE-2026-20259P4MEDIUMCVSS 5.5≥ 10.2, < 10.2.4≥ 10.0, < 10.0.72026-06-10
CVE-2026-20259 [MEDIUM] CWE-284 CVE-2026-20259: In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4 In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability `edit_saved_search_owner` could reassign saved search ownership to users outside their author
nvd
CVE-2026-76341P4MEDIUMCVSS 5.4≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76341 [MEDIUM] CWE-863 CVE-2026-76341: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a Table Editor dataset and share the dataset. A user who holds the "admin" Splunk role triggers the SPL when that user opens the dataset in the Table Editor. The SPL runs
nvd
CVE-2026-76339P4MEDIUMCVSS 5.4≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76339 [MEDIUM] CWE-77 CVE-2026-76339: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject arbitrary Search Processing Language (SPL) commands through the geostats command. The injected SPL runs with the permissions of another authenticated user after that user initiates the attacker-controlled g
nvd
CVE-2025-20384P4MEDIUMCVSS 5.3≥ 10.0, < 10.0.1≥ 9.4, < 9.4.6+2 more2025-12-03
CVE-2025-20384 [MEDIUM] CWE-117 CVE-2025-20384: In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform vers In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files due to improper validation at the /en-US/static/ web endpoint. This may a
nvd
CVE-2026-76337P4MEDIUMCVSS 5.3≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76337 [MEDIUM] CWE-22 CVE-2026-76337: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability is possible because Splunk Web does not restrict static file requests to the configured static directory.
nvd
CVE-2026-76340P4MEDIUMCVSS 5.3≥ 10.4, < 10.4.22026-08-19
CVE-2026-76340 [MEDIUM] CWE-862 CVE-2026-76340: In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterpri In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. The vulnerability does not affect Splunk Enterprise versions below 10.4. The vulnerability is possible because the REST API does not require authentication or the
nvd
CVE-2026-20139P4MEDIUMCVSS 4.3≥ 10.0, < 10.0.2≥ 9.4, < 9.4.8+2 more2026-02-18
CVE-2026-20139 [MEDIUM] CWE-400 CVE-2026-20139: In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platf In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload into the `realname`, `tz`, or `email` parameters of the `/splunkd/
nvd
CVE-2024-36986P4MEDIUMCVSS 5.7≥ 9.2, < 9.2.2≥ 9.1, < 9.1.5+1 more2024-07-01
CVE-2024-36986 [MEDIUM] CWE-200 CVE-2024-36986: In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions belo In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user
nvd
CVE-2026-76263P4MEDIUMCVSS 5.4≥ 10.4, < 10.4.2≥ 10.2, < 10.2.62026-08-19
CVE-2026-76263 [MEDIUM] CWE-639 CVE-2026-76263: In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "powe In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing Language version 2 (SPL2) modules belonging to other users through the data management orchestrator interface. The vulnerability does not affect Splunk Enterprise versions below 10.2. The broken object le
nvd
CVE-2026-76342P4MEDIUMCVSS 5.4≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76342 [MEDIUM] CWE-863 CVE-2026-76342: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store risky Search Processing Language (SPL) commands in a Table Editor dataset and share the dataset. A user who holds the "admin" Splunk role triggers the commands when that user opens the dataset in the Table Editor. The commands
nvd
Splunk Enterprise vulnerabilities | cvebase