Splunk

Splunk

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:40
  • Zuletzt bearbeitet 26.08.2026 16:16:40

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store risky Search Processing Language (SPL) commands in a Table Editor dataset and share the dataset. A user who holds the "admin"...

  • EPSS 0.27%
  • Veröffentlicht 19.08.2026 21:34:40
  • Zuletzt bearbeitet 26.08.2026 16:16:40

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint, a...

  • EPSS 0.23%
  • Veröffentlicht 19.08.2026 21:34:39
  • Zuletzt bearbeitet 26.08.2026 16:16:40

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a Table Editor dataset and share the dataset. A user who holds the "a...

  • EPSS 0.18%
  • Veröffentlicht 19.08.2026 21:34:38
  • Zuletzt bearbeitet 26.08.2026 16:16:40

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject arbitrary Search Processing Language (SPL) commands through the geostats command. The injected SPL runs ...

  • EPSS 0.27%
  • Veröffentlicht 19.08.2026 21:34:38
  • Zuletzt bearbeitet 26.08.2026 16:16:40

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. The vulnerability does not affect Splunk Enterprise versions b...

  • EPSS 0.3%
  • Veröffentlicht 19.08.2026 21:34:37
  • Zuletzt bearbeitet 26.08.2026 16:16:40

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability is possible because Splunk Web does not restrict static file reques...

  • EPSS 0.28%
  • Veröffentlicht 19.08.2026 21:34:37
  • Zuletzt bearbeitet 27.08.2026 17:20:16

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity,...

  • EPSS 0.24%
  • Veröffentlicht 19.08.2026 21:34:36
  • Zuletzt bearbeitet 26.08.2026 16:16:40

In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module managem...

  • EPSS 0.12%
  • Veröffentlicht 19.08.2026 21:34:35
  • Zuletzt bearbeitet 27.08.2026 17:20:15

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticate...

  • EPSS 0.33%
  • Veröffentlicht 19.08.2026 21:34:35
  • Zuletzt bearbeitet 27.08.2026 17:20:15

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. Whe...