Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Splunk Enterprise — Vulnerabilities & Security Advisories 221

All 221 CVE vulnerabilities found in Splunk Enterprise, with AI-generated Chinese analysis, references, and POCs.

This page documents known weaknesses in Splunk Enterprise, a software product developed by Splunk Inc. It aggregates vulnerability data associated with Common Weakness Enumeration classifications and specific software tags relevant to the application’s architecture and deployment models. The content covers publicly disclosed security issues and internal advisory reports spanning from the initial release of the software through the present day. Readers can use this resource to track a vendor's advisories, understand the impact and characteristics of a specific weakness class, or look up a product's vulnerability history. By consolidating information from multiple sources, this aggregation provides a comprehensive view of the security posture of Splunk Enterprise over time. The data includes details on affected versions, remediation steps, and references to external security bulletins. This approach facilitates better risk assessment for security professionals managing Splunk deployments. It allows users to identify patterns in defect discovery and prioritize patching efforts based on the severity and prevalence of the vulnerabilities. The page serves as a neutral repository for factual security information, enabling users to make informed decisions about system updates and configuration changes. It does not interpret the severity levels but presents the available evidence for each reported issue.

Vendor: Splunk Inc.

CVE ID Title CVSS Severity Published
CVE-2026-76325 Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise CWE-79 7.3 High 2026-08-19
CVE-2026-76324 Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk Enterprise CWE-79 5.7 Medium 2026-08-19
CVE-2026-76323 SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk Enterprise CWE-20 6.4 Medium 2026-08-19
CVE-2026-76322 SPL Injection through Dashboard Studio Search Query Options in Splunk Enterprise CWE-862 6.7 Medium 2026-08-19
CVE-2026-76321 SPL Injection through Nearby Event Searches in Splunk Enterprise CWE-77 7.3 High 2026-08-19
CVE-2026-76320 SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk Enterprise CWE-943 5.9 Medium 2026-08-19
CVE-2026-76318 Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise CWE-79 5.7 Medium 2026-08-19
CVE-2026-76319 Remote Code Execution (RCE) through Federated Search in Splunk Enterprise CWE-862 8.8 High 2026-08-19
CVE-2026-76317 Path Traversal through the Lookup Configuration REST API in Splunk Enterprise CWE-26 8.8 High 2026-08-19
CVE-2026-76315 Code Injection through Splunk Web Manager Configuration in Splunk Enterprise CWE-94 8.8 High 2026-08-19
CVE-2026-76316 Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise CWE-943 8.8 High 2026-08-19
CVE-2026-76313 Remote Code Execution (RCE) through the REST API in Splunk Enterprise CWE-284 8.8 High 2026-08-19
CVE-2026-76314 Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise CWE-94 8.8 High 2026-08-19
CVE-2026-76312 Improper Access Control through Embedded Reports in Splunk Enterprise CWE-284 9.4 Critical 2026-08-19
CVE-2026-76311 Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise CWE-284 9.4 Critical 2026-08-19
CVE-2026-76310 Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise CWE-284 9.4 Critical 2026-08-19
CVE-2026-76309 Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise CWE-89 4.3 Medium 2026-08-19
CVE-2026-76263 Improper Access Control through the REST API in Splunk Enterprise CWE-639 5.4 Medium 2026-08-19
CVE-2026-76262 Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk Enterprise CWE-200 7.5 High 2026-08-19
CVE-2026-76260 Incorrect Permission Assignment for Critical Resource through the REST API in Splunk Enterprise CWE-732 6.5 Medium 2026-08-19
CVE-2026-76261 Insecure Default Access Control List through the REST API in Splunk Secure Gateway CWE-732 5.3 Medium 2026-08-19
CVE-2026-76258 Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway CWE-321 6.5 Medium 2026-08-19
CVE-2026-76259 Improper Privilege Management on the Management Port in Splunk Enterprise for Windows CWE-269 8.8 High 2026-08-19
CVE-2026-76257 Missing Authorization through REST API Endpoints in Splunk Secure Gateway CWE-862 6.5 Medium 2026-08-19
CVE-2026-76256 Information Exposure through REST API Endpoints in Splunk Secure Gateway CWE-200 4.3 Medium 2026-08-19
CVE-2026-76255 Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise CWE-862 6.4 Medium 2026-08-19
CVE-2026-76253 Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterprise CWE-269 8.8 High 2026-08-19
CVE-2026-76254 SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise CWE-943 7.5 High 2026-08-19
CVE-2026-76252 Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk Enterprise CWE-79 6.8 Medium 2026-08-19
CVE-2026-76251 Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability Cloud CWE-862 7.1 High 2026-08-19

All 221 known CVE vulnerabilities affecting Splunk Enterprise with full Chinese analysis, references, and POCs where available.