Splunk

Splunk

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:46
  • Zuletzt bearbeitet 21.08.2026 19:14:02

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could create or modify a scripted lookup through generic configuration endpoints and run an installed lookup script w...

  • EPSS 0.28%
  • Veröffentlicht 19.08.2026 21:34:46
  • Zuletzt bearbeitet 21.08.2026 19:13:59

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster ...

  • EPSS 0.23%
  • Veröffentlicht 19.08.2026 21:34:45
  • Zuletzt bearbeitet 21.08.2026 19:17:12

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to ca...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:44
  • Zuletzt bearbeitet 21.08.2026 19:12:01

In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running arbitrary Search Processing Language (SPL) commands using the permissions of the authenticated user through a craft...

  • EPSS 0.28%
  • Veröffentlicht 19.08.2026 21:34:44
  • Zuletzt bearbeitet 21.08.2026 19:14:17

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure Portable Document Format (PDF) attachments in the email alert action workflow. When the email alert a...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:43
  • Zuletzt bearbeitet 21.08.2026 19:17:09

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in ...

  • EPSS 0.23%
  • Veröffentlicht 19.08.2026 21:34:43
  • Zuletzt bearbeitet 21.08.2026 19:14:31

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Cluster member control endpoints a...

  • EPSS 0.18%
  • Veröffentlicht 19.08.2026 21:34:42
  • Zuletzt bearbeitet 21.08.2026 19:14:40

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the browser of another user w...

  • EPSS 0.29%
  • Veröffentlicht 19.08.2026 21:34:41
  • Zuletzt bearbeitet 26.08.2026 16:16:41

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Repr...

  • EPSS 0.4%
  • Veröffentlicht 19.08.2026 21:34:41
  • Zuletzt bearbeitet 21.08.2026 19:09:24

In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage search head clustering could use the search head cluster member bundle Representational State Transfer (REST) API to write files to locations that th...