CVE-2026-20166
- EPSS 0.15%
- Veröffentlicht 11.03.2026 16:18:17
- Zuletzt bearbeitet 24.03.2026 19:55:36
In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve the Observability...
CVE-2026-20164
- EPSS 0.23%
- Veröffentlicht 11.03.2026 16:18:01
- Zuletzt bearbeitet 24.03.2026 17:13:12
In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.11, and 9.3.2411.123, a low-privileged user that does not hold the "admin" or "power" Splunk roles co...
CVE-2026-20165
- EPSS 0.17%
- Veröffentlicht 11.03.2026 16:17:54
- Zuletzt bearbeitet 24.03.2026 17:55:15
In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, and 9.3.2411.124, a low-privileged user that does not hold the "admin" or "power" Splunk roles co...
CVE-2026-20139
- EPSS 4.86%
- Veröffentlicht 18.02.2026 16:45:32
- Zuletzt bearbeitet 20.02.2026 13:47:44
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user that does not hold the "admin" or "power" Splunk rol...
CVE-2026-20144
- EPSS 0.36%
- Veröffentlicht 18.02.2026 16:45:23
- Zuletzt bearbeitet 23.02.2026 14:43:22
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role ...
CVE-2026-20137
- EPSS 0.22%
- Veröffentlicht 18.02.2026 16:45:17
- Zuletzt bearbeitet 20.02.2026 13:53:39
In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the "admin" or "power" Splunk role...
CVE-2025-20388
- EPSS 0.36%
- Veröffentlicht 03.12.2025 17:00:59
- Zuletzt bearbeitet 05.12.2025 17:11:26
In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.7, and 9.3.2411.116, a user who holds a role that contains the high privilege capability `change_authentication` cou...
CVE-2025-20389
- EPSS 0.41%
- Veröffentlicht 03.12.2025 17:00:55
- Zuletzt bearbeitet 05.12.2025 17:05:57
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles...
CVE-2025-20383
- EPSS 0.3%
- Veröffentlicht 03.12.2025 17:00:36
- Zuletzt bearbeitet 05.12.2025 18:30:13
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscri...
CVE-2025-20384
- EPSS 0.39%
- Veröffentlicht 03.12.2025 17:00:34
- Zuletzt bearbeitet 25.09.2026 23:10:00
In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape ...