在 Splunk Enterprise 10.4.2、10.2.6、10.0.9 和 9.4.14 之前的版本中,拥有 schedule_search 权限的用户可以在电子邮件告警操作工作流中配置可移植文档格式(PDF)附件。当电子邮件告警操作执行时,系统可能会以系统级特权执行任意搜索处理语言(SPL)命令,暴露所有相关数据,并影响搜索头(Search Head)的系统完整性和可用性。 该漏洞之所以存在,是因为在渲染 PDF 附件时,搜索调度程序传递的是系统级认证上下文,而非告警操作所有者的认证上下文。 有关更多信
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4< 10.4.2 |
affected |
10.2< 10.2.6 |
affected | ||
10.0< 10.0.9 |
affected | ||
9.4< 9.4.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4 ~ 10.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76312 | 9.4 CRITICAL | Improper Access Control through Embedded Reports in Splunk Enterprise |
| CVE-2026-76311 | 9.4 CRITICAL | Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise |
| CVE-2026-76310 | 9.4 CRITICAL | Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise |
| CVE-2026-76404 | 9.1 CRITICAL | Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server |
| CVE-2026-76319 | 8.8 HIGH | Remote Code Execution (RCE) through Federated Search in Splunk Enterprise |
| CVE-2026-76316 | 8.8 HIGH | Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise |
| CVE-2026-76351 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secu |
| CVE-2026-76389 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for En |
| CVE-2026-76253 | 8.8 HIGH | Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterpr |
| CVE-2026-76315 | 8.8 HIGH | Code Injection through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76395 | 8.8 HIGH | Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading |
| CVE-2026-76313 | 8.8 HIGH | Remote Code Execution (RCE) through the REST API in Splunk Enterprise |
| CVE-2026-76335 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76314 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76259 | 8.8 HIGH | Improper Privilege Management on the Management Port in Splunk Enterprise for Windows |
| CVE-2026-76317 | 8.8 HIGH | Path Traversal through the Lookup Configuration REST API in Splunk Enterprise |
| CVE-2026-76352 | 8.8 HIGH | Improper Authorization through the REST API in Splunk Enterprise |
| CVE-2026-76391 | 8.3 HIGH | Improper Privilege Management through Agent Run History in Splunk AI Toolkit |
| CVE-2026-76394 | 8.3 HIGH | Missing Authorization in Container and Connection Management through the REST API in Splun |
| CVE-2026-76402 | 8.2 HIGH | Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka |
Showing top 20 of 110 CVEs. View all on vendor page → →
No comments yet