CVE-2026-76351
- EPSS 0.23%
- Veröffentlicht 19.08.2026 21:34:45
- Zuletzt bearbeitet 21.08.2026 04:18:24
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to ca...
CVE-2026-76347
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:43
- Zuletzt bearbeitet 20.08.2026 17:19:42
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in ...
CVE-2026-76327
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:31
- Zuletzt bearbeitet 20.08.2026 13:01:19
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a cr...
CVE-2026-76261
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:18
- Zuletzt bearbeitet 20.08.2026 14:27:18
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, ...
CVE-2026-76258
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:16
- Zuletzt bearbeitet 20.08.2026 14:53:07
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and c...
CVE-2026-76256
- EPSS 0.22%
- Veröffentlicht 19.08.2026 21:34:15
- Zuletzt bearbeitet 20.08.2026 14:54:14
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup L...
CVE-2026-76257
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:15
- Zuletzt bearbeitet 20.08.2026 14:53:35
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Ga...
CVE-2026-20251
- EPSS 18.99%
- Veröffentlicht 10.06.2026 17:16:00
- Zuletzt bearbeitet 15.06.2026 17:08:59
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privil...
CVE-2025-20389
- EPSS 0.41%
- Veröffentlicht 03.12.2025 17:00:55
- Zuletzt bearbeitet 05.12.2025 17:05:57
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles...
CVE-2025-20383
- EPSS 0.3%
- Veröffentlicht 03.12.2025 17:00:36
- Zuletzt bearbeitet 05.12.2025 18:30:13
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscri...