在 Splunk Enterprise Security 8.6.1 以下版本中,拥有 ess_analyst 角色的用户能够修改用户与实体行为分析(UEBA)搜索宏。这些搜索宏以管理员权限执行计划搜索,从而导致攻击者可通过这些搜索访问所有相关数据,并破坏系统完整性。 该漏洞的根本原因在于,UEBA 应用的元数据错误地赋予分析师角色对搜索宏的写入权限,而按照安全要求,这些搜索宏应仅允许管理员角色进行写入。 更多信息请参阅 Splunk 官方文档中的“Splunk Enterprise Security 用户与角色”
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk Enterprise Security | 8.6< 8.6.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise Security | 8.6 ~ 8.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76312 | 9.4 CRITICAL | Improper Access Control through Embedded Reports in Splunk Enterprise |
| CVE-2026-76310 | 9.4 CRITICAL | Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise |
| CVE-2026-76311 | 9.4 CRITICAL | Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise |
| CVE-2026-76404 | 9.1 CRITICAL | Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server |
| CVE-2026-76316 | 8.8 HIGH | Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise |
| CVE-2026-76351 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secu |
| CVE-2026-76350 | 8.8 HIGH | Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk En |
| CVE-2026-76389 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for En |
| CVE-2026-76253 | 8.8 HIGH | Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterpr |
| CVE-2026-76315 | 8.8 HIGH | Code Injection through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76395 | 8.8 HIGH | Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading |
| CVE-2026-76319 | 8.8 HIGH | Remote Code Execution (RCE) through Federated Search in Splunk Enterprise |
| CVE-2026-76313 | 8.8 HIGH | Remote Code Execution (RCE) through the REST API in Splunk Enterprise |
| CVE-2026-76314 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76317 | 8.8 HIGH | Path Traversal through the Lookup Configuration REST API in Splunk Enterprise |
| CVE-2026-76259 | 8.8 HIGH | Improper Privilege Management on the Management Port in Splunk Enterprise for Windows |
| CVE-2026-76335 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76352 | 8.8 HIGH | Improper Authorization through the REST API in Splunk Enterprise |
| CVE-2026-76394 | 8.3 HIGH | Missing Authorization in Container and Connection Management through the REST API in Splun |
| CVE-2026-76391 | 8.3 HIGH | Improper Privilege Management through Agent Run History in Splunk AI Toolkit |
Showing top 20 of 110 CVEs. View all on vendor page → →
No comments yet