Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76361 | LOW | 2.7 | In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections … | Aug 19, 2026 |
| CVE-2026-76360 | MEDIUM | 4.3 | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that … | Aug 19, 2026 |
| CVE-2026-76359 | MEDIUM | 6.5 | In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to … | Aug 19, 2026 |
| CVE-2026-76358 | MEDIUM | 6.5 | In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the intended temporary … | Aug 19, 2026 |
| CVE-2026-76357 | HIGH | 7.6 | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) … | Aug 19, 2026 |
| CVE-2026-76356 | HIGH | 8.1 | In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint … | Aug 19, 2026 |
| CVE-2026-76355 | HIGH | 7.5 | In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer … | Aug 19, 2026 |
| CVE-2026-76354 | HIGH | 8.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system … | Aug 19, 2026 |
| CVE-2026-76353 | MEDIUM | 5.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a … | Aug 19, 2026 |
| CVE-2026-76352 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could create or … | Aug 19, 2026 |
| CVE-2026-76351 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not … | Aug 19, 2026 |
| CVE-2026-76350 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure Portable Document Format … | Aug 19, 2026 |
| CVE-2026-76349 | MEDIUM | 6.4 | In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running arbitrary Search Processing Language (SPL) commands … | Aug 19, 2026 |
| CVE-2026-76348 | LOW | 3.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send … | Aug 19, 2026 |
| CVE-2026-76347 | MEDIUM | 5.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not … | Aug 19, 2026 |
| CVE-2026-76346 | MEDIUM | 5.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard … | Aug 19, 2026 |
| CVE-2026-76345 | MEDIUM | 6.0 | In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage search head clustering could use the search head cluster … | Aug 19, 2026 |
| CVE-2026-76344 | HIGH | 7.7 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch … | Aug 19, 2026 |
| CVE-2026-76343 | MEDIUM | 6.5 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute attacker-chosen … | Aug 19, 2026 |
| CVE-2026-76342 | MEDIUM | 5.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store risky Search Processing Language (SPL) … | Aug 19, 2026 |
| CVE-2026-76341 | MEDIUM | 5.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) … | Aug 19, 2026 |
| CVE-2026-76340 | MEDIUM | 5.3 | In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. … | Aug 19, 2026 |
| CVE-2026-76339 | MEDIUM | 5.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject arbitrary … | Aug 19, 2026 |
| CVE-2026-76338 | HIGH | 8.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge … | Aug 19, 2026 |
| CVE-2026-76337 | MEDIUM | 5.3 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability … | Aug 19, 2026 |