Splunk Splunk Enterprise是美国Splunk公司的日志分析系统。 Splunk Enterprise存在信息泄露漏洞,该漏洞源于 SPL命令返回 REST端点结果中的 字段,可能导致低权限用户查看存储的凭据哈希。以下版本受到影响:10.4.1之前版本、10.2.5之前版本、10.0.8之前版本、9.4.13之前版本。Splunk Cloud Platform存在安全漏洞,以
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk Cloud Platform | 10.5.2605< 10.5.2605.0 |
affected |
10.4.2604< 10.4.2604.6 |
affected | ||
10.3.2512< 10.3.2512.15 |
affected | ||
10.2.2510< 10.2.2510.18 |
affected | ||
10.1.2507< 10.1.2507.24 |
affected | ||
| Splunk | Splunk Enterprise | 10.4< 10.4.1 |
affected |
10.2< 10.2.5 |
affected | ||
10.0< 10.0.8 |
affected | ||
9.4< 9.4.13 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4 ~ 10.4.1 | - |
|
| Splunk | Splunk Cloud Platform | 10.5.2605 ~ 10.5.2605.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20296 | 8.3 HIGH | SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Serv |
| CVE-2026-20297 | 7.2 HIGH | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enter |
No comments yet