CVE-2026-76274
- EPSS -
- Veröffentlicht 07.10.2026 20:46:34
- Zuletzt bearbeitet 07.10.2026 21:17:18
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Trans...
CVE-2026-76275
- EPSS -
- Veröffentlicht 07.10.2026 20:46:34
- Zuletzt bearbeitet 07.10.2026 21:17:18
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search query text and job metadata for jobs that belong to other users, including job identifiers, disp...
CVE-2026-76273
- EPSS -
- Veröffentlicht 07.10.2026 20:46:33
- Zuletzt bearbeitet 07.10.2026 21:17:18
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to add attacker-controlled content to system-level messag...
CVE-2026-76270
- EPSS -
- Veröffentlicht 07.10.2026 20:46:32
- Zuletzt bearbeitet 07.10.2026 21:17:17
In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (RE...
CVE-2026-76271
- EPSS -
- Veröffentlicht 07.10.2026 20:46:32
- Zuletzt bearbeitet 07.10.2026 21:17:18
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause a denial of service against a Representational State Transfer (REST) API endpoint in the Discove...
CVE-2026-76269
- EPSS -
- Veröffentlicht 07.10.2026 20:46:31
- Zuletzt bearbeitet 07.10.2026 21:17:17
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs that belong ...
CVE-2026-76267
- EPSS -
- Veröffentlicht 07.10.2026 20:46:30
- Zuletzt bearbeitet 07.10.2026 21:17:17
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could inject forged entries into the app log through the Representational State Transfer (REST) API. The vulnerability is ...
CVE-2026-76264
- EPSS -
- Veröffentlicht 07.10.2026 20:46:28
- Zuletzt bearbeitet 07.10.2026 21:17:17
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible ...
CVE-2026-76354
- EPSS 0.24%
- Veröffentlicht 19.08.2026 21:34:47
- Zuletzt bearbeitet 21.08.2026 19:19:17
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API reques...
CVE-2026-76355
- EPSS 0.35%
- Veröffentlicht 19.08.2026 21:34:47
- Zuletzt bearbeitet 26.08.2026 16:16:41
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer (REST) API endpoint when Edge Processor is turned on...