Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Splunk Enterprise — Vulnerabilities & Security Advisories 221

All 221 CVE vulnerabilities found in Splunk Enterprise, with AI-generated Chinese analysis, references, and POCs.

This page documents known weaknesses in Splunk Enterprise, a software product developed by Splunk Inc. It aggregates vulnerability data associated with Common Weakness Enumeration classifications and specific software tags relevant to the application’s architecture and deployment models. The content covers publicly disclosed security issues and internal advisory reports spanning from the initial release of the software through the present day. Readers can use this resource to track a vendor's advisories, understand the impact and characteristics of a specific weakness class, or look up a product's vulnerability history. By consolidating information from multiple sources, this aggregation provides a comprehensive view of the security posture of Splunk Enterprise over time. The data includes details on affected versions, remediation steps, and references to external security bulletins. This approach facilitates better risk assessment for security professionals managing Splunk deployments. It allows users to identify patterns in defect discovery and prioritize patching efforts based on the severity and prevalence of the vulnerabilities. The page serves as a neutral repository for factual security information, enabling users to make informed decisions about system updates and configuration changes. It does not interpret the severity levels but presents the available evidence for each reported issue.

Vendor: Splunk Inc.

CVE ID Title CVSS Severity Published
CVE-2026-76355 Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk Enterprise CWE-306 7.5 High 2026-08-19
CVE-2026-76353 Path Traversal through Knowledge Bundle Replication in Splunk Enterprise CWE-24 5.4 Medium 2026-08-19
CVE-2026-76354 Path Traversal through Search Head Clustering in Splunk Enterprise CWE-158 8.1 High 2026-08-19
CVE-2026-76352 Improper Authorization through the REST API in Splunk Enterprise CWE-285 8.8 High 2026-08-19
CVE-2026-76351 Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway CWE-918 8.8 High 2026-08-19
CVE-2026-76350 Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk Enterprise CWE-269 8.8 High 2026-08-19
CVE-2026-76348 Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise CWE-862 3.8 Low 2026-08-19
CVE-2026-76349 SPL Injection through Splunk Web Form Tokens in Splunk Enterprise CWE-943 6.4 Medium 2026-08-19
CVE-2026-76347 Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway CWE-918 5.4 Medium 2026-08-19
CVE-2026-76346 Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise CWE-79 5.4 Medium 2026-08-19
CVE-2026-76345 Remote Code Execution (RCE) through the REST API in Splunk Enterprise CWE-284 6.0 Medium 2026-08-19
CVE-2026-76343 Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise CWE-89 6.5 Medium 2026-08-19
CVE-2026-76344 Path Traversal through the Search Dispatch REST API in Splunk Enterprise CWE-27 7.7 High 2026-08-19
CVE-2026-76342 Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise CWE-863 5.4 Medium 2026-08-19
CVE-2026-76341 Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk Enterprise CWE-863 5.4 Medium 2026-08-19
CVE-2026-76340 Missing Authorization for Reloading Token-Signing Keys through the REST API in Splunk Enterprise CWE-862 5.3 Medium 2026-08-19
CVE-2026-76339 SPL Injection through the geostats Command in Splunk Enterprise CWE-77 5.4 Medium 2026-08-19
CVE-2026-76338 Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise CWE-287 8.1 High 2026-08-19
CVE-2026-76337 Path Traversal through Splunk Web Static File Serving in Splunk Enterprise CWE-22 5.3 Medium 2026-08-19
CVE-2026-76335 Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise CWE-94 8.8 High 2026-08-19
CVE-2026-76336 Improper Access Control through the REST API in Splunk Enterprise CWE-862 7.1 High 2026-08-19
CVE-2026-76333 Stored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk Enterprise CWE-79 7.1 High 2026-08-19
CVE-2026-76334 SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise CWE-352 6.4 Medium 2026-08-19
CVE-2026-76332 SPL Injection through Splunk Web in Splunk Enterprise CWE-20 7.1 High 2026-08-19
CVE-2026-76330 SPL Injection through Monitoring Console Forwarder Filters in Splunk Enterprise CWE-20 7.1 High 2026-08-19
CVE-2026-76331 SPL Injection through the REST API in Splunk Enterprise CWE-943 8.1 High 2026-08-19
CVE-2026-76329 SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise CWE-943 6.4 Medium 2026-08-19
CVE-2026-76328 SPL Injection through Splunk Web in Splunk Enterprise CWE-77 6.7 Medium 2026-08-19
CVE-2026-76327 SPL Injection through Splunk Web in Splunk Secure Gateway CWE-943 6.4 Medium 2026-08-19
CVE-2026-76326 Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Splunk Enterprise CWE-79 5.7 Medium 2026-08-19

All 221 known CVE vulnerabilities affecting Splunk Enterprise with full Chinese analysis, references, and POCs where available.