CVE-2026-20139
- EPSS 0.09%
- Veröffentlicht 18.02.2026 16:45:32
- Zuletzt bearbeitet 20.02.2026 13:47:44
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user that does not hold the "admin" or "power" Splunk rol...
CVE-2026-20144
- EPSS 0.08%
- Veröffentlicht 18.02.2026 16:45:23
- Zuletzt bearbeitet 23.02.2026 14:43:22
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role ...
CVE-2026-20141
- EPSS 0.05%
- Veröffentlicht 18.02.2026 16:45:21
- Zuletzt bearbeitet 23.02.2026 14:46:16
In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access the Splunk Monitoring Console App endpoints due to an improper access control. This could lead to a sen...
CVE-2026-20137
- EPSS 0.04%
- Veröffentlicht 18.02.2026 16:45:17
- Zuletzt bearbeitet 20.02.2026 13:53:39
In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the "admin" or "power" Splunk role...
CVE-2025-20388
- EPSS 0.03%
- Veröffentlicht 03.12.2025 17:00:59
- Zuletzt bearbeitet 05.12.2025 17:11:26
In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.7, and 9.3.2411.116, a user who holds a role that contains the high privilege capability `change_authentication` cou...
CVE-2025-20389
- EPSS 0.12%
- Veröffentlicht 03.12.2025 17:00:55
- Zuletzt bearbeitet 05.12.2025 17:05:57
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles...
CVE-2025-20387
- EPSS 0.03%
- Veröffentlicht 03.12.2025 17:00:51
- Zuletzt bearbeitet 05.12.2025 17:35:09
In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation d...
CVE-2025-20383
- EPSS 0.04%
- Veröffentlicht 03.12.2025 17:00:36
- Zuletzt bearbeitet 05.12.2025 18:30:13
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscri...
CVE-2025-20384
- EPSS 0.12%
- Veröffentlicht 03.12.2025 17:00:34
- Zuletzt bearbeitet 05.12.2025 18:14:07
In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape ...
CVE-2025-20386
- EPSS 0.03%
- Veröffentlicht 03.12.2025 17:00:31
- Zuletzt bearbeitet 05.12.2025 17:51:41
In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. T...