CVE-2026-76332
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:34
- Zuletzt bearbeitet 27.08.2026 17:20:14
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Analytics Workspace. When the authenticated user opens the link, Splunk Enterprise runs a...
CVE-2026-76333
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:34
- Zuletzt bearbeitet 26.08.2026 16:16:40
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action with a crafted Uniform Resource Locator (URL). When another authenticated user selects the...
CVE-2026-76331
- EPSS 0.23%
- Veröffentlicht 19.08.2026 21:34:33
- Zuletzt bearbeitet 27.08.2026 17:20:14
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject Search Processing Language (SPL) into saved-search dispatch requests. This could allow for unauthorized ...
CVE-2026-76329
- EPSS 0.2%
- Veröffentlicht 19.08.2026 21:34:32
- Zuletzt bearbeitet 26.08.2026 16:16:39
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role into opening a crafted link to Monitoring Console. When that user opens the link, Splunk Enterprise r...
CVE-2026-76330
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:32
- Zuletzt bearbeitet 27.08.2026 17:20:13
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console. When the authenticated user opens the link, Splunk Enterprise runs at...
CVE-2026-76327
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:31
- Zuletzt bearbeitet 26.08.2026 16:16:39
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a cr...
CVE-2026-76328
- EPSS 0.2%
- Veröffentlicht 19.08.2026 21:34:31
- Zuletzt bearbeitet 27.08.2026 17:20:13
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a dashboard. When another authenticated user exports the dashboard as...
CVE-2026-76326
- EPSS 0.24%
- Veröffentlicht 19.08.2026 21:34:30
- Zuletzt bearbeitet 26.08.2026 16:16:39
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could store a dashboard view that runs JavaScript in the browser of another user who opens it and hovers over a spark...
CVE-2026-76324
- EPSS 0.3%
- Veröffentlicht 19.08.2026 21:34:29
- Zuletzt bearbeitet 26.08.2026 16:16:39
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could create a malicious Splunk Web tour and cause arbitrary JavaScript to run in the browser of another user when that user opens a craf...
CVE-2026-76325
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:29
- Zuletzt bearbeitet 26.08.2026 16:16:39
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour knowledge object that matches an auto-tour page name and share the object at the app level. The object ca...