Výsledky hledání

výrobce: Splunk× v celém archivu zrušit filtry

37 karet z 37 položek CZ · EN/orig

1

2

Splunk security advisory (AV26-838)

Serial Number: AV26-838Date: August 21, 2026 As of August 19, 2026, Splunk is affected by vulnerabilities in the following products: Cisco Talos Intelligence for Enterprise Security Cloud Prior to 1.0.3 Splunk Enterprise Prior to 10.0.9 Prior to 10.2.6 Prior to 10.4.1 Prior to 10.4.2 Prior to 9.4.14 Splunk MCP Server app Prior to 1.2.1 Splunk Universal Forwarder Prior to 10.4.2 Prior to 10.2.6 Prior to 10.0.9 Prior to 9.4.14 Splunk SOAR Prior to 8.6.0 Splunk SOAR Connectors Multiple versions…

Splunk CA

· Cyber Centre Kanada · Splunk security advisory (AV26-838)

NCSC-2026-0322 [1.00] [M/H] Kwetsbaarheden verholpen in Splunk Enterprise door Splunk

Splunk heeft meerdere kwetsbaarheden verholpen in Splunk Enterprise, specifiek in versies vóór 10.4.2, 10.2.6, 10.0.9 en 9.4.14. De kwetsbaarheden in Splunk Enterprise betreffen onder andere: - Onvoldoende handhaving van authenticatie- en autorisatiecontroles in REST API's, waardoor niet-bevoegde gebruikers toegang kunnen krijgen tot gevoelige data, configuraties en kunnen leiden tot het uitvoeren van willekeurige SPL-commando's met verhoogde privileges. - Meerdere kwetsbaarheden die Cross-Site…

Splunk NL

· NCSC-NL · NCSC-2026-0322 [1.00] [M/H] Kwetsbaarheden verholpen in Splunk Enterprise door Splunk

3

Splunk Enterprise: Security Hardening Release - August 2026

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.4, CVEs: CVE-2026-76338, CVE-2026-76352, CVE-2026-76310, CVE-2026-76311, CVE-2026-76312, CVE-2026-76253, CVE-2026-76259, CVE-2026-76313, CVE-2026-76314, CVE-2026-76315, CVE-2026-76316, CVE-2026-76317, CVE-2026-76319, CVE-2026-76335, CVE-2026-76350, CVE-2026-76351, CVE-2026-76331, CVE-2026-76354, CVE-2026-76344, CVE-2026-76254 (+40 other associated CVEs), Summary: Splunk addressed multiple vulnerabilities…

CVSS 9.4 Splunk FI

· NCSC-FI · Splunk Enterprise: Security Hardening Release - August 2026

8

SVD-2026-0804: Security Hardening Release for Splunk SOAR - August 2026

Splunk addressed multiple vulnerabilities in Splunk SOAR 8.6.0. See CVE Details for vulnerability-specific information.

EPSS 0.00 CVE-2026-76356 CVE-2026-76357 CVE-2026-76358 CVE-2026-76359 CVE-2026-76360 CVE-2026-76361 CVE-2026-76362 CVE-2026-76363 CVE-2026-76364 CVE-2026-76365 CVE-2026-76366 CVE-2026-76367 CVE-2026-76368 CVE-2026-76369 CVE-2026-76370 Splunk US

· Splunk Advisories · SVD-2026-0804: Security Hardening Release for Splunk SOAR - August 2026

SVD-2026-0806: Security Hardening Release for Splunk SOAR Connectors - August 2026

Splunk addressed multiple vulnerabilities in Splunk SOAR Connectors. See CVE Details for vulnerability-specific and product-specific information.

EPSS 0.00 CVE-2026-76371 CVE-2026-76372 CVE-2026-76373 CVE-2026-76374 CVE-2026-76375 CVE-2026-76376 CVE-2026-76377 CVE-2026-76378 CVE-2026-76379 CVE-2026-76380 CVE-2026-76381 CVE-2026-76382 CVE-2026-76383 CVE-2026-76384 CVE-2026-76385 CVE-2026-76386 Splunk US

· Splunk Advisories · SVD-2026-0806: Security Hardening Release for Splunk SOAR Connectors - August 2026

SVD-2026-0808: Security Hardening Release for Splunk Apps and Add-ons - August 2026

Splunk addressed multiple vulnerabilities in Splunk apps and add-ons. See CVE Details for vulnerability and product specific information.

EPSS 0.01 CVE-2026-76389 CVE-2026-76390 CVE-2026-76391 CVE-2026-76392 CVE-2026-76393 CVE-2026-76394 CVE-2026-76395 CVE-2026-76396 CVE-2026-76397 CVE-2026-76398 CVE-2026-76399 CVE-2026-76400 CVE-2026-76401 CVE-2026-76402 CVE-2026-76403 CVE-2026-76404 CVE-2026-76405 Splunk US

· Splunk Advisories · SVD-2026-0808: Security Hardening Release for Splunk Apps and Add-ons - August 2026

5

SVD-2026-0702: SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the list_deployment_server capability into running arbitrary Search Processing Language (SPL) searches on their behalf as splunk-system-user, allowing for access to stored credentials and indexed data.The vulnerability is possible because Deployment Server…

EPSS 0.00 CVE-2026-20296 Splunk US

· Splunk Advisories · SVD-2026-0702: SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise

SVD-2026-0703: Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the edit_local_apps and install_apps capabilities could cause a legitimate app installation to write files outside the intended app directory, into $SPLUNK_HOME/etc/ and its subdirectories.The vulnerability is caused by a path traversal in the app installation workflow, which does…

EPSS 0.01 CVE-2026-20297 Splunk US

· Splunk Advisories · SVD-2026-0703: Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise

SVD-2026-0704: Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could view stored credential hashes when they access the /servicesNS/-/-/storage/passwords REST endpoint through the |rest Search Processing Language (SPL) command.The exposure happens because the |rest SPL command returns the encr…

EPSS 0.00 CVE-2026-20298 Splunk US

· Splunk Advisories · SVD-2026-0704: Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise

1

2

SVD-2026-0613: Insecure Default Domain Allowlist in Splunk AI Toolkit

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the “admin” or “power” Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration. The vulnerability exists because of an insecure default domain allowlist in the Splunk AI Toolkit, which does not restrict outbound AI agent requests to approved external domains.

EPSS 0.00 CVE-2026-20265 Splunk US

· Splunk Advisories · SVD-2026-0613: Insecure Default Domain Allowlist in Splunk AI Toolkit

SVD-2026-0614: OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit

In Splunk AI Toolkit versions below 5.7.4, a user who holds the “admin” Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.

EPSS 0.01 CVE-2026-20266 Splunk US

· Splunk Advisories · SVD-2026-0614: OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit

12

SVD-2026-0601: Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV…

EPSS 0.32 CVE-2026-20251 Splunk US

· Splunk Advisories · SVD-2026-0601: Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway

SVD-2026-0602: Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privileged user that does not hold the “admin” or “power” Splunk roles could send server-side requests to arbitrary internal destinations through the Dashboard Studio PDF export feature. The vulnerability exists because the trusted-domain validation uses a prefix match that can be bypassed with attacker…

EPSS 0.00 CVE-2026-20252 Splunk US

· Splunk Advisories · SVD-2026-0602: Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise

SVD-2026-0603: Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

KEV ✓ EPSS 0.97 CVE-2026-20253 Splunk US

· Splunk Advisories · SVD-2026-0603: Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

SVD-2026-0604: Information Disclosure through External Content Restriction Bypass in Splunk Enterprise

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could craft a malicious classic dashboard that exfiltrates sensitive data to an external server when a higher-privileged user views it, bypassing the external content restriction through a Cascading Style Sheets (CSS) injection.The Trusted Domains…

EPSS 0.00 CVE-2026-20254 Splunk US

· Splunk Advisories · SVD-2026-0604: Information Disclosure through External Content Restriction Bypass in Splunk Enterprise

SVD-2026-0605: Improper Input Validation through Classic Dashboards in Splunk Enterprise

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the “admin” or “power” Splunk roles could craft a malicious classic dashboard that exfiltrates sensitive data to an external server. The vulnerability exists because URL validation on the external content dialog is incomplete, which can allow for requests to untrusted domains when a…

EPSS 0.00 CVE-2026-20255 Splunk US

· Splunk Advisories · SVD-2026-0605: Improper Input Validation through Classic Dashboards in Splunk Enterprise

SVD-2026-0606: Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause data exfiltration through classic dashboards by redirecting a victim to an external site using a protocol-relative URL in a drill-down link.The vulnerability exists because the URL classifier in classic dashboards only recognizes http://…

EPSS 0.00 CVE-2026-20256 Splunk US

· Splunk Advisories · SVD-2026-0606: Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise

SVD-2026-0607: Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the “admin” or “power” Splunk roles could craft a classic dashboard that exfiltrates sensitive data from the browser of a higher-privileged user who views it. The exfiltration is possible because classic dashboard panels do not fully validate style attribute values, which can allow…

EPSS 0.00 CVE-2026-20257 Splunk US

· Splunk Advisories · SVD-2026-0607: Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise

SVD-2026-0608: Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the “admin” or “power” Splunk roles could store a malicious script in a classic dashboard HTML panel, causing unauthorized JavaScript code to execute in the browser of another user. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request…

EPSS 0.00 CVE-2026-20258 Splunk US

· Splunk Advisories · SVD-2026-0608: Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise

SVD-2026-0609: Improper Access Control in Splunk Enterprise

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability edit_saved_search_owner could reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks access control.

EPSS 0.00 CVE-2026-20259 Splunk US

· Splunk Advisories · SVD-2026-0609: Improper Access Control in Splunk Enterprise

SVD-2026-0611: Log Injection through HTTP Request Paths in Splunk SOAR

In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR application log files through specially crafted HTTP request paths, which a terminal emulator might interpret when an administrator views the logs.The injection is possible because SOAR does not strip control characters from HTTP request paths before writing them to application logs.

EPSS 0.00 CVE-2026-20260 Splunk US

· Splunk Advisories · SVD-2026-0611: Log Injection through HTTP Request Paths in Splunk SOAR

2

SVD-2026-0515: Third-Party Package Updates in Splunk User Behavior Analytics - May 2026

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk User Behavior Analytics versions 5.4.5, and higher.

EPSS 0.88 CVE-2021-23358 CVE-2022-45868 CVE-2023-5590 CVE-2024-29371 CVE-2024-3651 CVE-2024-37891 CVE-2024-5535 CVE-2025-11226 CVE-2025-4565 CVE-2025-47273 CVE-2025-49146 CVE-2025-49844 CVE-2025-58057 CVE-2025-66516 CVE-2025-7338 CVE-2026-25639 Splunk US

· Splunk Advisories · SVD-2026-0515: Third-Party Package Updates in Splunk User Behavior Analytics - May 2026

1

LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout

When a company suffers a cyber breach, its stock price often takes a hit, but the timing, depth, and duration of that reaction are far less predictable. In this LABScon25 presentation, Mick Baccio and Scott Roberts explore whether public indicators of breach activity can be used to anticipate market response before formal disclosure. Drawing on sources such as EDGAR filings, executive blog posts, and social media chatter, the speakers examine how public breadcrumbs can reveal incident activity…

SentinelOne Splunk GitHub Apple US

· SentinelLabs · LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout