CVE-2026-76258
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:16
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and c...
CVE-2026-76256
- EPSS 0.22%
- Veröffentlicht 19.08.2026 21:34:15
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup L...
CVE-2026-76257
- EPSS 0.25%
- Veröffentlicht 19.08.2026 21:34:15
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Ga...
CVE-2026-76254
- EPSS 0.29%
- Veröffentlicht 19.08.2026 21:34:14
- Zuletzt bearbeitet 27.08.2026 17:20:02
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) pipelines from Dataset Explorer with the same privileges as that u...
CVE-2026-76255
- EPSS 0.22%
- Veröffentlicht 19.08.2026 21:34:14
- Zuletzt bearbeitet 27.08.2026 17:20:04
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power" Splunk roles could trick another user into running arbitrary Search Processing Language (SPL) commands through the Data Model Edit...
CVE-2026-76253
- EPSS 0.34%
- Veröffentlicht 19.08.2026 21:34:13
- Zuletzt bearbeitet 27.08.2026 17:20:01
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read eve...
CVE-2026-76251
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:12
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Sp...
CVE-2026-76252
- EPSS 0.24%
- Veröffentlicht 19.08.2026 21:34:12
- Zuletzt bearbeitet 26.08.2026 16:16:38
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user into visiting a malicious web page could run unauthorized JavaScript in that user's browser. This could allow for unauthorized acc...
CVE-2026-20298
- EPSS 0.23%
- Veröffentlicht 15.07.2026 17:18:32
- Zuletzt bearbeitet 24.07.2026 18:11:49
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' S...
CVE-2026-20296
- EPSS 0.23%
- Veröffentlicht 15.07.2026 17:18:23
- Zuletzt bearbeitet 24.07.2026 18:18:34
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_d...