CVE-2026-76313
- EPSS 0.5%
- Veröffentlicht 19.08.2026 21:34:22
- Zuletzt bearbeitet 27.08.2026 17:20:08
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by dist...
CVE-2026-76311
- EPSS 0.37%
- Veröffentlicht 19.08.2026 21:34:21
- Zuletzt bearbeitet 27.08.2026 17:20:07
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all rele...
CVE-2026-76312
- EPSS 0.36%
- Veröffentlicht 19.08.2026 21:34:21
- Zuletzt bearbeitet 27.08.2026 17:20:07
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant d...
CVE-2026-76309
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:20
- Zuletzt bearbeitet 26.08.2026 16:16:39
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the "admin" or "power" Splunk roles could inject Structured Query Language (SQL) through the Representational State Transfer (REST) API, ...
CVE-2026-76310
- EPSS 0.37%
- Veröffentlicht 19.08.2026 21:34:20
- Zuletzt bearbeitet 27.08.2026 17:20:06
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant da...
CVE-2026-76262
- EPSS 0.37%
- Veröffentlicht 19.08.2026 21:34:19
- Zuletzt bearbeitet 26.08.2026 20:18:00
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. Th...
CVE-2026-76263
- EPSS 0.22%
- Veröffentlicht 19.08.2026 21:34:19
- Zuletzt bearbeitet 26.08.2026 20:18:00
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing Language version 2 (SPL2) modules belonging to other users through the data management orchestrator int...
CVE-2026-76261
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:18
- Zuletzt bearbeitet 26.08.2026 20:18:00
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, ...
CVE-2026-76259
- EPSS 0.13%
- Veröffentlicht 19.08.2026 21:34:17
- Zuletzt bearbeitet 27.08.2026 17:20:06
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child pro...
CVE-2026-76260
- EPSS 0.26%
- Veröffentlicht 19.08.2026 21:34:17
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the rest_properties_get capability could read encrypted stored credentials through the Representational State Transfer (REST) API. Successful exploi...