在 Splunk Enterprise 低于 10.4.2、10.2.6、10.0.9 和 9.4.14 的版本中,未经身份验证但拥有嵌入式报告令牌(embedded report token)的用户可以下载相关的搜索作业分发包归档文件(search job dispatch archive),恢复会话材料,并利用其访问报告所有者可使用的全部相关数据,从而影响系统完整性。当报告所有者拥有 Splunk “admin”角色时,攻击者甚至可能执行管理操作。该漏洞的存在是因为嵌入式报告访问机制未阻止通过表示状态传输(RE
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4< 10.4.2 |
affected |
10.2< 10.2.6 |
affected | ||
10.0< 10.0.9 |
affected | ||
9.4< 9.4.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4 ~ 10.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76312 | 9.4 CRITICAL | Improper Access Control through Embedded Reports in Splunk Enterprise |
| CVE-2026-76311 | 9.4 CRITICAL | Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise |
| CVE-2026-76404 | 9.1 CRITICAL | Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server |
| CVE-2026-76316 | 8.8 HIGH | Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise |
| CVE-2026-76351 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secu |
| CVE-2026-76350 | 8.8 HIGH | Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk En |
| CVE-2026-76389 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for En |
| CVE-2026-76253 | 8.8 HIGH | Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterpr |
| CVE-2026-76315 | 8.8 HIGH | Code Injection through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76395 | 8.8 HIGH | Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading |
| CVE-2026-76319 | 8.8 HIGH | Remote Code Execution (RCE) through Federated Search in Splunk Enterprise |
| CVE-2026-76317 | 8.8 HIGH | Path Traversal through the Lookup Configuration REST API in Splunk Enterprise |
| CVE-2026-76314 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76259 | 8.8 HIGH | Improper Privilege Management on the Management Port in Splunk Enterprise for Windows |
| CVE-2026-76335 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76352 | 8.8 HIGH | Improper Authorization through the REST API in Splunk Enterprise |
| CVE-2026-76313 | 8.8 HIGH | Remote Code Execution (RCE) through the REST API in Splunk Enterprise |
| CVE-2026-76394 | 8.3 HIGH | Missing Authorization in Container and Connection Management through the REST API in Splun |
| CVE-2026-76391 | 8.3 HIGH | Improper Privilege Management through Agent Run History in Splunk AI Toolkit |
| CVE-2026-76402 | 8.2 HIGH | Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka |
Showing top 20 of 110 CVEs. View all on vendor page → →
No comments yet