These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An executive overview of CVE-2026-76401: In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event delivery for the affected connector. This vulnerability is a denial- [truncated]
An AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-76400 affects Splunk Connect for Kafka versions below 2.2.7, allowing an unauthenticated user who can reach the Kafka Connect REST API and influence responses from an HTTP Event Collector endpoint to cause the connector to retry failed event batches until event delivery stops. This occurs because HTTP Event Collector delivery [truncated]
In Splunk AI Toolkit versions below 6.0.1, a user who holds the 'power' Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner. This could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the 'power' Splunk role permission to modify sched [truncated]
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the 'admin' or 'power' Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. This could lead to unau [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:26.023Z and has not been modified since then. This vulnerability affects Splunk AI Toolkit versions below 6.0.0, allowing a user with the 'power' Splunk role to execute arbitrary code by loading a crafted model file. The deserialization of untrusted sparse matrix data is possible due to a l [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:25.737Z and has not been modified since then. This race condition vulnerability in Splunk AI Toolkit versions below 6.0.0 allows a user to overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name. The issue arises because the toolkit do [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:25.613Z and has not been modified since then. This vulnerability affects Splunk AI Toolkit versions below 6.0.0, allowing users without 'admin' or 'power' roles to obtain predictable or default credentials for connected container services. The issue arises from hard-coded or predictable def [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:25.487Z and has not been modified since then. This vulnerability affects Splunk AI Toolkit versions below 6.0.0, allowing users without 'admin' or 'power' roles to run searches with system-level privileges due to improper privilege management. The issue arises from the Agent Run History han [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:25.357Z and has not been modified since then. This vulnerability exists in Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, allowing unauthenticated users to access the OpenAPI specification through Splunk Web static file paths. This could enable reconnaissance o [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:25.220Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, allowing a user with the get_talos_enrichment capability to send a crafted request to the Talos intellig [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:25.090Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Splunk Enterprise Security versions below 8.6.1, allowing users with the ess_analyst role to change UEBA search macros, potentially leading to unauthorized data access and system in [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:22.153Z and has not been modified since then. Splunk SOAR versions below 8.6.0 contain a Cross-Site Scripting (XSS) vulnerability. An Incident Commander role user can store JavaScript in a note, potentially running it in another user's browser when they open the note. However, exploitation [truncated]
A vulnerability in Splunk SOAR versions below 8.6.0 allows users with the 'Automation Engineer' role to run arbitrary SQL statements against the Splunk SOAR database, potentially leading to data tampering or unauthorized access. This issue arises from the incorporation of user-supplied input into database queries without proper neutralization. Organizations using Splunk SOAR versions below 8.6.0, particul [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:21.397Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability exists in Splunk SOAR versions below 8.6.0, where an administrator can use the /rest/support/connectivity/.../check_connectivity endpoint to initiate outbound network connections to arbitra [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:21.267Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Splunk SOAR versions below 8.6.0, allowing authenticated users with no role assigned to gather system and cluster telemetry that should be restricted to administrative or support us [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:21.130Z and has not been modified since then. The NVD entry is currently Analyzed. In Splunk SOAR versions below 8.6.0, a user with the Administrator role can exploit a path traversal vulnerability in the Universal Forwarder installer's archive extraction. This allows writing files outside [truncated]
A path traversal vulnerability exists in Splunk SOAR versions below 8.6.0, allowing a user with app-install privileges to write files outside the intended temporary directory during app installation. The vulnerability is due to the archive extraction routine not validating that extracted file paths stay within the intended destination directory. This issue can lead to unauthorized file overwrites or data [truncated]
An authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code in Splunk SOAR versions below 8.6.0. This vulnerability exists because the REST API does not require an assigned role for the request and does not restrict the user-supplied file path to the intended temporary directory, allowing potential attackers to e [truncated]
CVE-2026-76354 is a high-severity vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user without 'admin' or 'power' roles can send crafted REST API requests to delete or overwrite files writable by the user account running Splunk processes on non-captain search head cluster members. This is due to Search Head Clustering bundle replication not validating bundle file na [truncated]
A user without 'admin' or 'power' Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager, affecting system integrity and disrupting service. This is due to knowledge bundle delta processing not restricting removal paths to the staging directory and the endpoint not enforcing the expected authorization boundary.
A user without 'admin' or 'power' Splunk roles could create or modify a scripted lookup, potentially allowing access to relevant data and affecting system integrity and availability. This vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 due to insufficient capability enforcement on generic transforms configuration endpoints. Exploitation could lead to unauthorize [truncated]
A vulnerability in Splunk Secure Gateway and Splunk Enterprise could allow a user without 'admin' or 'power' roles to modify the Splunk platform configuration by crafting report notification data. This is due to Splunk Secure Gateway not validating decoded report notification identifiers before using them to construct requests to the Splunk Enterprise REST API.
The CVE-2026-76350 vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. It allows users with the schedule_search capability to execute arbitrary Search Processing Language (SPL) commands with system-level privileges when rendering PDF attachments in email alert actions. This issue is caused by the search scheduler passing a system-level authentication context instead [truncated]
In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into running arbitrary Search Processing Language (SPL) commands using the permissions of the authenticated user through a crafted Splunk Web link. The SPL commands could access all relevant data. The vulnerability requires the attacker to phish the user by tricking them into opening t [truncated]
A user without admin or power Splunk roles could exploit Server-Side Request Forgery (SSRF) in report notifications to send authenticated requests to internal Splunk services, potentially altering Search Head Cluster state and causing denial of service. This is due to Splunk Secure Gateway's failure to validate report notification path values before sending internal requests. The affected Splunk Enterpris [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:19.427Z and has not been modified since then. This vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role could store a malicious script in dashboard sparkline format options and execute unauthorized JavaScript in the b [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:19.297Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Splunk Enterprise versions below 10.4.2 and allows users with high-privilege roles to write files to certain locations via the search head cluster member bundle REST API, potentiall [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:19.150Z and has not been modified since then. This vulnerability affects Splunk Enterprise instances, particularly those with user roles restricted to prevent administrative actions. A user without 'admin' or 'power' roles could write dispatch metadata to an arbitrary location by supplying [truncated]
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the 'admin' or 'power' Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint. This vulnerability allows for access to substantially all data stored by Data Orchestration, including jobs owned by other users and stored connection credenti [truncated]
The CVE-2026-76341 vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A user with the 'power' Splunk role can store attacker-controlled Search Processing Language (SPL) in a Table Editor dataset and share it. A user with the 'admin' Splunk role triggers the SPL when opening the dataset, which runs with the permissions of the second user, potentially exposing all r [truncated]