CVE-2026-76387
- EPSS 0.28%
- Veröffentlicht 19.08.2026 21:35:07
- Zuletzt bearbeitet 21.08.2026 04:18:25
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for...
CVE-2026-76388
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:35:07
- Zuletzt bearbeitet 21.08.2026 04:18:25
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allo...
CVE-2024-22164
- EPSS 0.46%
- Veröffentlicht 09.01.2024 17:15:12
- Zuletzt bearbeitet 03.06.2025 15:15:57
In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an at...
CVE-2024-22165
- EPSS 0.52%
- Veröffentlicht 09.01.2024 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:55:43
In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations manager until...