在 Splunk Enterprise 10.4.3、10.2.7、10.0.10 和 9.4.15 以下版本,以及 Splunk Secure Gateway 3.10.11、3.9.25 和 3.8.72 以下版本中,未拥有 “admin” 或 “sc_admin” Splunk 角色的已认证用户能够修改 Splunk Secure Gateway 警报和移动设备收件人数据,这些数据存储在应用键值存储(KV Store)的集合中,供后续的警报和订阅工作流使用。该漏洞的存在是因为受影响的集合允许无限制的写访问权限
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4 ~ 10.4.3 | - |
|
| Splunk | Splunk Secure Gateway | 3.10 ~ 3.10.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76268 | 9.8 CRITICAL | Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise |
| CVE-2026-76266 | 7.7 HIGH | Local Privilege Escalation through Linux Package Upgrades in Splunk Enterprise |
| CVE-2026-76265 | 6.5 MEDIUM | Improper Access Control through REST API Endpoints in Splunk Secure Gateway |
| CVE-2026-76274 | 6.5 MEDIUM | Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observabi |
| CVE-2026-76269 | 6.5 MEDIUM | Improper Access Control in Search Job Retrieval through the REST API in Splunk Enterprise |
| CVE-2026-76270 | 6.5 MEDIUM | Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splunk Enterprise |
| CVE-2026-76271 | 6.5 MEDIUM | Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Splunk Enterpri |
| CVE-2026-76286 | 5.3 MEDIUM | Server-Side Request Forgery (SSRF) through Custom API Tools in Splunk MCP Server |
| CVE-2026-76278 | 4.3 MEDIUM | Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise |
| CVE-2026-76272 | 4.3 MEDIUM | Missing Access Control through the REST API in Splunk Secure Gateway |
| CVE-2026-76267 | 4.3 MEDIUM | Log Injection through the REST API in Splunk App for Splunk O11y Cloud |
| CVE-2026-76264 | 4.3 MEDIUM | Improper Authorization through the REST API in Splunk Enterprise |
| CVE-2026-76276 | 4.3 MEDIUM | Information Disclosure in the Discover Splunk Observability Cloud app through Splunk Web f |
| CVE-2026-76275 | 4.3 MEDIUM | Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise |
| CVE-2026-76273 | 4.3 MEDIUM | Improper Input Validation through the collect Command in Splunk Enterprise |
| CVE-2026-76279 | 4.3 MEDIUM | Improper Input Validation of Index Names through the collect Command in Splunk Enterprise |
| CVE-2026-76277 | 4.1 MEDIUM | Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterp |
| CVE-2026-76281 | Improper Access Control in Splunk Enterprise | |
| CVE-2026-76284 | Improper Neutralization in Splunk Enterprise | |
| CVE-2026-76283 | Protection Mechanism Failure in Splunk Enterprise |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet