CVEs we hold for Splunk
Records whose assigning authority named Splunk as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-76405Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) appSplunk On-Call (VictorOps)
CVE-2026-76404Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server appSplunk MCP Server app
CVE-2026-76403Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for KafkaSplunk Connect for Kafka
CVE-2026-76402Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for KafkaSplunk Connect for Kafka
CVE-2026-76401Regular Expression Denial of Service (DoS) through the REST API in Splunk Connect for KafkaSplunk Connect for Kafka
CVE-2026-76400Denial of Service (DoS) through the REST API in Splunk Connect for KafkaSplunk Connect for Kafka
CVE-2026-76399Incorrect Permission Assignment for Scheduled Searches in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76398Improper Access Control during Experiment History Deletion through the REST API in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76397Improper Access Control in Experiment History through the REST API in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76396Improper Access Control through Scheduled Searches in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76395Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76394Missing Authorization in Container and Connection Management through the REST API in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76393Race Condition during Model Upload through the REST API in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76392Use of Hard-coded Credentials in Container Connections in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76391Improper Privilege Management through Agent Run History in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-76390Information Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security CloudSplunk Cisco Talos Intelligence for Enterprise Security…
CVE-2026-76389Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for Enterprise Security CloudSplunk Cisco Talos Intelligence for Enterprise Security…
CVE-2026-76388Privilege Escalation through Search Macro Permissions in Splunk Enterprise SecuritySplunk Enterprise Security
CVE-2026-76387SPL Injection through the REST API in Splunk Enterprise SecuritySplunk Enterprise Security
CVE-2026-76386Information Disclosure through Action Parameters in Zoom app for Splunk SOARSplunk SOAR
CVE-2026-76385Information Disclosure through Action Parameters in Venafi app for Splunk SOARSplunk SOAR
CVE-2026-76384Information Disclosure through Action Parameters in Splunk Attack Analyzer Connector for Splunk SOARSplunk SOAR
CVE-2026-76383Information Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOARSplunk SOAR
CVE-2026-76382Information Disclosure through Action Parameters in Phantom app for Splunk SOARSplunk SOAR
CVE-2026-76381Information Disclosure through Action Parameters in MS Graph for Active Directory app for Splunk SOARSplunk SOAR
CVE-2026-76380Information Disclosure through Action Parameters in CrowdStrike OAuth API app for Splunk SOARSplunk SOAR
CVE-2026-76379Information Disclosure through Action Parameters in Cisco Webex app for Splunk SOARSplunk SOAR
CVE-2026-76378Information Disclosure through Action Parameters in Cisco Secure Malware Analytics app for Splunk SOARSplunk SOAR
CVE-2026-76377Information Disclosure through Action Parameters in Azure AD Graph app for Splunk SOARSplunk SOAR
CVE-2026-76376Information Disclosure through Action Parameters in AWS IAM app for Splunk SOARSplunk SOAR
CVE-2026-76375Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOARSplunk SOAR
CVE-2026-76374Information Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOARSplunk SOAR
CVE-2026-76372Incorrect Permission Assignment through Safe Mode in Nmap Scanner for Splunk SOARSplunk Nmap Scanner
CVE-2026-76371Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOARSplunk FireAMP
CVE-2026-76365Structured Query Language (SQL) Injection through Custom Lists in Splunk SOARSplunk SOAR
CVE-2026-76364Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOARSplunk SOAR
CVE-2026-76362Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOARSplunk SOAR
CVE-2026-76361Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOARSplunk SOAR
CVE-2026-76360Information Disclosure through Missing Authorization in the Health REST API in Splunk SOARSplunk SOAR
CVE-2026-76359Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOARSplunk SOAR
CVE-2026-76357Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOARSplunk SOAR
CVE-2026-76356Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOARSplunk SOAR
CVE-2026-76355Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk EnterpriseSplunk Enterprise
CVE-2026-76353Path Traversal through Knowledge Bundle Replication in Splunk EnterpriseSplunk Enterprise
CVE-2026-76351Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure GatewaySplunk Secure Gateway
CVE-2026-76350Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk EnterpriseSplunk Enterprise
CVE-2026-76348Missing Authorization in Search Head Cluster Member Controls in Splunk EnterpriseSplunk Enterprise
CVE-2026-76347Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure GatewaySplunk Secure Gateway
CVE-2026-76346Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk EnterpriseSplunk Enterprise
CVE-2026-76345Remote Code Execution (RCE) through the REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76344Path Traversal through the Search Dispatch REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76343Structured Query Language (SQL) Injection through the REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76342Risky Commands Safeguards Bypass through Splunk Web in Splunk EnterpriseSplunk Enterprise
CVE-2026-76341Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk EnterpriseSplunk Enterprise
CVE-2026-76340Missing Authorization for Reloading Token-Signing Keys through the REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76338Improper Authentication through REST API Distributed Search Token Requests in Splunk EnterpriseSplunk Enterprise
CVE-2026-76337Path Traversal through Splunk Web Static File Serving in Splunk EnterpriseSplunk Enterprise
CVE-2026-76335Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk EnterpriseSplunk Enterprise
CVE-2026-76334SPL Injection through Dashboard Studio Workflow Actions in Splunk EnterpriseSplunk Enterprise
CVE-2026-76333Stored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk EnterpriseSplunk Enterprise
CVE-2026-76330SPL Injection through Monitoring Console Forwarder Filters in Splunk EnterpriseSplunk Enterprise
CVE-2026-76329SPL Injection through Monitoring Console Dashboard Inputs in Splunk EnterpriseSplunk Enterprise
CVE-2026-76326Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Splunk EnterpriseSplunk Enterprise
CVE-2026-76325Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk EnterpriseSplunk Enterprise
CVE-2026-76324Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk EnterpriseSplunk Enterprise
CVE-2026-76323SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk EnterpriseSplunk Enterprise
CVE-2026-76322SPL Injection through Dashboard Studio Search Query Options in Splunk EnterpriseSplunk Enterprise
CVE-2026-76320SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk EnterpriseSplunk Enterprise
CVE-2026-76319Remote Code Execution (RCE) through Federated Search in Splunk EnterpriseSplunk Enterprise
CVE-2026-76318Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk EnterpriseSplunk Enterprise
CVE-2026-76317Path Traversal through the Lookup Configuration REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76316Stored SPL Injection through Deployment Server Broker Registration in Splunk EnterpriseSplunk Enterprise
CVE-2026-76315Code Injection through Splunk Web Manager Configuration in Splunk EnterpriseSplunk Enterprise
CVE-2026-76314Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk EnterpriseSplunk Enterprise
CVE-2026-76313Remote Code Execution (RCE) through the REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76312Improper Access Control through Embedded Reports in Splunk EnterpriseSplunk Enterprise
CVE-2026-76311Improper Access Control in Embedded Report Dispatch Archives in Splunk EnterpriseSplunk Enterprise
CVE-2026-76310Improper Access Control through Embedded Report REST API Requests in Splunk EnterpriseSplunk Enterprise
CVE-2026-76309Structured Query Language (SQL) Injection through the REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76262Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76261Insecure Default Access Control List through the REST API in Splunk Secure GatewaySplunk Secure Gateway
CVE-2026-76260Incorrect Permission Assignment for Critical Resource through the REST API in Splunk EnterpriseSplunk Enterprise
CVE-2026-76259Improper Privilege Management on the Management Port in Splunk Enterprise for WindowsSplunk Enterprise
CVE-2026-76258Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure GatewaySplunk Secure Gateway
CVE-2026-76257Missing Authorization through REST API Endpoints in Splunk Secure GatewaySplunk Secure Gateway
CVE-2026-76256Information Exposure through REST API Endpoints in Splunk Secure GatewaySplunk Secure Gateway
CVE-2026-76255Risky Command Safeguards Bypass through Splunk Web in Splunk EnterpriseSplunk Enterprise
CVE-2026-76254SPL Command Safeguards Bypass through Splunk Web in Splunk EnterpriseSplunk Enterprise
CVE-2026-76253Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk EnterpriseSplunk Enterprise
CVE-2026-76252Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk EnterpriseSplunk Enterprise
CVE-2026-76251Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability CloudSplunk Enterprise
CVE-2026-20298Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20296SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20266OS Command Injection in the btool Configuration Helper in Splunk AI ToolkitSplunk AI Toolkit
CVE-2026-20258Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20257Improper Input Validation through Classic Dashboard CSS in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20256Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20255Improper Input Validation through Classic Dashboards in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20254Information Disclosure through External Content Restriction Bypass in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20253Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk EnterpriseSplunk Enterprise
CVE-2026-20252Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20251Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure GatewaySplunk Secure Gateway
CVE-2026-20240Denial of Service through coldToFrozen.sh Script in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20239Sensitive Information Disclosure through Log Files in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20238Improper Access Control through Role Inheritance in Splunk AI Toolkit appSplunk AI Toolkit
CVE-2026-20205Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server appSplunk MCP Server
CVE-2026-20204Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20203Improper Access Control in Data Model Acceleration in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20202Improper Input Validation during User Account Creation in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20166Sensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20165Sensitive Information Disclosure in MongoClient logging channel in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20164Sensitive Information Disclosure through Improper Access Control in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20163Remote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20162Stored Cross-Site Scripting (XSS) through Path Traversal in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20144Sensitive Information Disclosure in ''_internal'' index in Splunk EnterpriseSplunk Cloud Platform
CVE-2026-20142Sensitive Information Disclosure in "_internal" index in Splunk EnterpriseSplunk Enterprise
CVE-2026-20139Client-Side Denial of Service (DoS) through ''/splunkd/__raw/services/authentication/users/username'' REST API endpoint…Splunk Cloud Platform
CVE-2026-20138Sensitive Information Disclosure in "_internal" index in Splunk EnterpriseSplunk Enterprise
CVE-2026-20137Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-22621Privilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOARSplunk App for SOAR
CVE-2025-20389Improper Input Validation in "label" column field in Splunk Secure Gateway AppSplunk Secure Gateway
CVE-2025-20388Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20387Incorrect permissions assignment on Splunk Universal Forwarder for Windows during new installation or upgradeSplunk Enterprise
CVE-2025-20386Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgradeSplunk Enterprise
CVE-2025-20385Stored Cross-Site scripting (XSS) through Anchor Tag "href" in Navigation Bar Collections in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20383Improper access control through push notifications for reports and alerts in Splunk Secure Gateway appSplunk Secure Gateway
CVE-2025-20382URL validation bypass through Views Dashboard in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20381SPL commands allowlist controls bypass in Splunk MCP Server app through "run_splunk_query" MCP toolSplunk MCP Server
CVE-2025-20379Risky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk…Splunk Cloud Platform
CVE-2025-20373Sensitive Information Disclosure in “_internal“ index through Splunk Add-On for Palo Alto NetworksSplunk Add-on for Palo Alto Networks
CVE-2025-20371Unauthenticated Blind Server Side Request Forgery (SSRF) in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20370Denial of Service (DoS) through Multiple LDAP Bind Requests in Splunk EnterpriseSplunk Enterprise Cloud
CVE-2025-20369Extensible Markup Language (XML) External Entity Injection (XXE) through Dashboard label field on Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20368Stored Cross-Site Scripting (XSS) through missing field warning messages in Saved Search and Job Inspector on Splunk…Splunk Cloud Platform
CVE-2025-20367Reflected Cross-site Scripting (XSS) in '/app/search/table' endpoint through the 'dataset.command' parameter on Splunk…Splunk Cloud Platform
CVE-2025-20366Improper Access Control in Background Job Submission in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20325Sensitive Information Disclosure in the SHCConfig logging channel in Clustered Deployments in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20324Improper Access Control in System Source Types Configuration in Splunk EnterpriseSplunk Enterprise Cloud
CVE-2025-20322Denial of Service (DoS) in Search Head Cluster through Cross-Site Request Forgery (CSRF) in Splunk EnterpriseSplunk Enterprise Cloud
CVE-2025-20321Membership State Change in Splunk Search Head Cluster through a Cross-Site Request Forgery (CSRF) in Splunk EnterpriseSplunk Enterprise Cloud
CVE-2025-20320Denial of Service (DoS) through “User Interface - Views“ configuration page in Splunk EnterpriseSplunk Enterprise Cloud
CVE-2025-20319Remote Command Execution through Scripted Input Files in Splunk EnterpriseSplunk Enterprise
CVE-2025-20300Improper Access Control Lets Low-Privilege Users Suppress Read-Only Alerts in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20298Incorrect permission assignment on Universal Forwarder for Windows during new installation or upgradeSplunk/UniversalForwarder for Windows
CVE-2025-20297Reflected Cross-Site Scripting (XSS) on Splunk Enterprise through dashboard PDF generation componentSplunk Cloud Platform
CVE-2025-20233Incorrect permissions set by the “chmod“ and “makedirs“ Python functions in Splunk App for Lookup File EditingSplunk App for Lookup File Editing
CVE-2025-20232Risky Command Safeguards Bypass in “/app/search/search“ endpoint through “s“ parameter in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20230Missing Access Control and Incorrect Ownership of Data in App Key Value Store (KVStore) collections in the Splunk…Splunk Secure Gateway
CVE-2025-20229Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-20228Maintenance mode state change of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF) in Splunk…Splunk Cloud Platform
CVE-2025-20227Information Disclosure through external content warning modal dialog box bypass in Splunk Enterprise Dashboard StudioSplunk Cloud Platform
CVE-2025-20226Risky command safeguards bypass in “/services/streams/search“ endpoint through “q“ parameter in Splunk EnterpriseSplunk Cloud Platform
CVE-2025-0367Regular Expression Denial of Service (ReDoS) in Splunk Supporting Add-on for Active Directory (SA-ldapsearch)Splunk Supporting Add-on for Active Directory
CVE-2024-53247Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway appSplunk Secure Gateway
CVE-2024-53245Information Disclosure due to Username Collision with a Role that has the same Name as the UserSplunk Cloud Platform
CVE-2024-53244Risky command safeguards bypass in “/en-US/app/search/report“ endpoint through “s“ parameterSplunk Cloud Platform
CVE-2024-53243Information Disclosure in Mobile Alert Responses in Splunk Secure GatewaySplunk Secure Gateway
CVE-2024-45741Persistent Cross-Site Scripting (XSS) via props.conf on Splunk EnterpriseSplunk Cloud Platform
CVE-2024-45740Persistent Cross-Site Scripting (XSS) through Scheduled Views on Splunk EnterpriseSplunk Cloud Platform
CVE-2024-45737Maintenance mode state change of App Key Value Store (KVStore) through Cross-Site Request Forgery (CSRF)Splunk Cloud Platform
CVE-2024-45736Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk DaemonSplunk Cloud Platform
CVE-2024-45735Improper Access Control for low-privileged user in Splunk Secure Gateway AppSplunk Secure Gateway
CVE-2024-45734Low Privilege User can View Images on the Host Machine by using the PDF Export feature in Splunk Classic DashboardSplunk Enterprise
CVE-2024-45733Remote Code Execution (RCE) due to insecure session storage configuration in Splunk Enterprise on WindowsSplunk Enterprise
CVE-2024-45732Low-privileged user could run search as nobody in SplunkDeploymentServerConfig appSplunk Cloud Platform
CVE-2024-45731Potential Remote Command Execution (RCE) through arbitrary file write to Windows system root directory when Splunk…Splunk Enterprise
CVE-2024-36997Persistent Cross-site Scripting (XSS) in conf-web/settings REST endpointSplunk Cloud Platform
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.