Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76405 | MEDIUM | 4.3 | In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a … | Aug 19, 2026 |
| CVE-2026-76404 | CRITICAL | 9.1 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. … | Aug 19, 2026 |
| CVE-2026-76403 | HIGH | 7.4 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from … | Aug 19, 2026 |
| CVE-2026-76402 | HIGH | 8.2 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a … | Aug 19, 2026 |
| CVE-2026-76401 | MEDIUM | 5.9 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp … | Aug 19, 2026 |
| CVE-2026-76400 | MEDIUM | 5.9 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses … | Aug 19, 2026 |
| CVE-2026-76399 | HIGH | 8.1 | In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing … | Aug 19, 2026 |
| CVE-2026-76398 | MEDIUM | 4.3 | In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of … | Aug 19, 2026 |
| CVE-2026-76397 | HIGH | 8.1 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, … | Aug 19, 2026 |
| CVE-2026-76396 | HIGH | 7.5 | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and … | Aug 19, 2026 |
| CVE-2026-76395 | HIGH | 8.8 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading … | Aug 19, 2026 |
| CVE-2026-76394 | HIGH | 8.3 | In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure … | Aug 19, 2026 |
| CVE-2026-76393 | MEDIUM | 5.9 | In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a … | Aug 19, 2026 |
| CVE-2026-76392 | MEDIUM | 5.4 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials … | Aug 19, 2026 |
| CVE-2026-76391 | HIGH | 8.3 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, … | Aug 19, 2026 |
| CVE-2026-76390 | MEDIUM | 5.3 | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file … | Aug 19, 2026 |
| CVE-2026-76389 | HIGH | 8.8 | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted … | Aug 19, 2026 |
| CVE-2026-76388 | HIGH | 8.1 | In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) … | Aug 19, 2026 |
| CVE-2026-76387 | HIGH | 8.1 | In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing … | Aug 19, 2026 |
| CVE-2026-76386 | MEDIUM | 4.3 | In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting … | Aug 19, 2026 |
| CVE-2026-76385 | MEDIUM | 4.3 | In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore … | Aug 19, 2026 |
| CVE-2026-76384 | MEDIUM | 4.3 | In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could … | Aug 19, 2026 |
| CVE-2026-76383 | MEDIUM | 4.3 | In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions … | Aug 19, 2026 |
| CVE-2026-76382 | MEDIUM | 4.3 | In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a … | Aug 19, 2026 |
| CVE-2026-76381 | MEDIUM | 4.3 | In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run … | Aug 19, 2026 |