These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A user without 'admin' or 'power' Splunk roles could inject arbitrary Search Processing Language (SPL) commands through the geostats command in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. The injected SPL runs with the permissions of another authenticated user after that user initiates the attacker-controlled geostats search in Splunk Web. This could expose all relevant data avail [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:18.360Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, allowing an unauthenticated user with access to a trusted distributed search private key to forge an administrat [truncated]
The CVE-2026-76336 vulnerability exists in Splunk Enterprise versions below 10.4.2 and 10.2.6. It allows users without 'admin' or 'power' roles to delete SPL2 modules across all apps and users through the SPL2 module management REST API, affecting system integrity and causing partial service disruption. This type of vulnerability typically arises from insufficient authorization and validation in the API. [truncated]
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the 'power' Splunk role could store a Dashboard Studio workflow action containing attacker-controlled Search Processing Language (SPL). When another authenticated user selects the action from Event Actions and selects Continue, Splunk Enterprise runs the injected SPL using the permissions of that user. The vulnerabili [truncated]
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user with the 'power' Splunk role can store a Dashboard Studio workflow action with a crafted URL. When another authenticated user selects the stored action, attacker-controlled JavaScript runs in the browser of that user, potentially exposing data or actions available through Splunk Web. The vulnerability requires the attacker to p [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:17.423Z and has not been modified since then. This vulnerability exists in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, allowing users without 'admin' or 'power' roles to inject SPL into saved-search dispatch requests. This could allow for unauthorized access to all [truncated]
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the 'admin' Splunk role into opening a crafted link to Monitoring Console. When that user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could expose data available to that user or modi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:17.033Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, allowing a user with the 'power' Splunk role to store attacker-controlled Search Processing Language (SPL) in a [truncated]
The CVE-2026-76327 vulnerability affects Splunk Enterprise and Splunk Secure Gateway, allowing an unauthenticated user to trick an admin or sc_admin user into opening a crafted URL, potentially leading to arbitrary Search Processing Language (SPL) command execution. This medium-severity vulnerability requires phishing and has significant operational impact. Affected versions include Splunk Enterprise belo [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:16.777Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, allowing a user without 'admin' or 'power' roles to store a dashboard view that runs JavaScript in another user' [truncated]
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a Cross-Site Scripting (XSS) vulnerability exists. A user with the 'power' Splunk role can store a malicious ui-tour knowledge object that matches an auto-tour page name and share it at the app level. This object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page, potent [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:14.580Z and has not been modified since then. The NVD entry is currently Analyzed. This SQL injection vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 allows a low-privileged user to inject SQL through the REST API, potentially leading to unauthorized dat [truncated]
A user with specific Splunk role capabilities could cause an app installation to write files outside the intended directory, potentially leading to unauthorized access or modifications. This vulnerability affects Splunk Enterprise and Splunk Cloud Platform versions, allowing an attacker to exploit the path traversal in the app installation workflow. Administrators and security teams should be aware of the [truncated]
CVE-2026-20253 is a critical vulnerability in Splunk Enterprise, classified as a Missing Authentication for Critical Function Vulnerability. The CVE record was published on 2026-06-18T00:00:00.000Z and has not been modified since then. The NVD entry is currently unclassified. This vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog, with a due date for remediation set for 2026-06-21.
A vulnerability in Splunk AI Toolkit versions below 5.7.4 allows low-privileged users to make outbound HTTP requests to attacker-controlled servers, potentially leading to data exfiltration. This is due to an insecure default domain allowlist that does not restrict outbound AI agent requests to approved external domains. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity.
CVE-2026-20260 is a log injection vulnerability in Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0. An unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR application log files through specially crafted HTTP request paths. A terminal emulator might interpret these codes when an administrator views the logs. The injec [truncated]
A vulnerability exists in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131. A user who holds a Splunk role that contains the high-privilege capability `edit_saved_search_owner` could reassign saved search ownership to users outside their authorized scope. The ownership reassign [truncated]
A vulnerability was found in Splunk Enterprise and Splunk Cloud Platform. A low-privileged user could craft a classic dashboard that exfiltrates sensitive data from the browser of a higher-privileged user who views it. This is possible because classic dashboard panels do not fully validate style attribute values, allowing requests to reach external domains outside the configured Trusted Domains List.
A vulnerability was found in Splunk Enterprise and Splunk Cloud Platform. The issue allows a low-privileged user to craft a malicious classic dashboard that can exfiltrate sensitive data to an external server. This is possible due to incomplete URL validation on the external content dialog, which can allow requests to untrusted domains when a user interacts with a crafted dashboard.
A vulnerability was discovered in Splunk Enterprise and Splunk Cloud Platform. A low-privileged user that does not hold the 'admin' or 'power' Splunk roles could send server-side requests to arbitrary internal destinations through the Dashboard Studio PDF export feature. The vulnerability exists due to trusted-domain validation using a prefix match that can be bypassed with attacker-controlled subdomains [truncated]
CVE-2026-20251 is a high-severity vulnerability affecting Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway. A low-privileged user without 'admin' or 'power' roles could exploit this vulnerability to achieve Remote Code Execution (RCE). The issue arises from the unsafe deserialization of App Key Value Store (KV Store) data via the 'jsonpickle' Python library.
CVE-2026-20240 was publicly published on 2026-05-20. According to the CVE description and NVD metadata, a low-privileged user who is not in the Splunk admin or power roles could cause a denial of service in affected Splunk Enterprise and Splunk Cloud Platform versions by abusing the coldToFrozen.sh script in the splunk_archiver app. The issue stems from missing input validation that allows arbitrary path [truncated]
CVE-2026-20239 was published on 2026-05-20 and describes a high-severity information exposure issue in Splunk Enterprise and Splunk Cloud Platform. According to the NVD record, a user whose role grants access to the _internal index could view session cookies and response bodies containing sensitive data. The reported CVSS v3.1 score is 7.5 (HIGH).
CVE-2026-20238 is a confidentiality issue in Splunk AI Toolkit versions below 5.7.3. A low-privileged user without the admin or power roles may access data that was intended to be restricted by srchFilter settings on custom roles. The issue arises because the app’s authorize.conf includes a srchFilter entry for the built-in user role, and Splunk’s search-filter inheritance behavior can combine filters in [truncated]
CVE-2017-5880 is a denial-of-service issue in Splunk Web. A remote authenticated user can send a crafted GET request that crashes the daemon, disrupting availability. The issue was publicly disclosed on 2017-02-04 and is rated CVSS 6.5 (Medium).