CVE-2026-76280
- EPSS -
- Veröffentlicht 07.10.2026 20:46:37
- Zuletzt bearbeitet 07.10.2026 21:17:19
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the "admin" or "sc_admin" Splunk roles could modify Splunk Secure G...
CVE-2026-76272
- EPSS -
- Veröffentlicht 07.10.2026 20:46:33
- Zuletzt bearbeitet 07.10.2026 21:17:18
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk...
CVE-2026-76265
- EPSS -
- Veröffentlicht 07.10.2026 20:46:29
- Zuletzt bearbeitet 07.10.2026 21:17:17
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk roles could access privileged Splunk Secure Gateway ...
CVE-2026-76351
- EPSS 0.23%
- Veröffentlicht 19.08.2026 21:34:45
- Zuletzt bearbeitet 21.08.2026 19:17:12
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to ca...
CVE-2026-76347
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:43
- Zuletzt bearbeitet 21.08.2026 19:17:09
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in ...
CVE-2026-76327
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:31
- Zuletzt bearbeitet 26.08.2026 16:16:39
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a cr...
CVE-2026-76261
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:18
- Zuletzt bearbeitet 26.08.2026 20:18:00
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, ...
CVE-2026-76258
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:16
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and c...
CVE-2026-76256
- EPSS 0.22%
- Veröffentlicht 19.08.2026 21:34:15
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup L...
CVE-2026-76257
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:15
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Ga...