CVE-2026-20298Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 07/15/2026 Severity Medium CVE-2026-20296SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 07/15/2026 Severity High CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 07/15/2026 Severity High CVE-2026-20258Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity High CVE-2026-20253Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise Exploitation status KEV Fix YesPublished 06/10/2026 Severity Critical CVE-2026-20252Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity High CVE-2026-20257Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20259Improper Access Control in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20255Improper Input Validation through Classic Dashboards in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20251Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity High CVE-2026-20254Information Disclosure through External Content Restriction Bypass in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20256Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20239Sensitive Information Disclosure through Log Files in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity High CVE-2026-20240Denial of Service through coldToFrozen.sh Script in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity High CVE-2026-20203Improper Access Control in Data Model Acceleration in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity Medium CVE-2026-20204Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity High CVE-2026-20202Improper Input Validation during User Account Creation in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity Medium CVE-2026-20163Remote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity High CVE-2026-20162Stored Cross-Site Scripting (XSS) through Path Traversal in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity Medium CVE-2026-20166Sensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity Medium CVE-2026-20164Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity Medium CVE-2026-20165Sensitive Information Disclosure in MongoClient logging channel in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity Medium CVE-2026-20139Client-Side Denial of Service (DoS) through ''/splunkd/__raw/services/authentication/users/username'' REST API endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Medium CVE-2026-20144Sensitive Information Disclosure in ''_internal'' index in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Medium CVE-2026-20137Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Low CVE-2025-20388Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Low CVE-2025-20389Improper Input Validation in "label" column field in Splunk Secure Gateway App Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Medium CVE-2025-20383Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Medium CVE-2025-20384Unauthenticated Log Injection in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Medium CVE-2025-20385Stored Cross-Site scripting (XSS) through Anchor Tag "href" in Navigation Bar Collections in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Low CVE-2025-20382URL validation bypass through Views Dashboard in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Low CVE-2025-20379Risky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 11/12/2025 Severity Low CVE-2025-20378Open Redirect on Web Login endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 11/12/2025 Severity Low CVE-2025-20368Stored Cross-Site Scripting (XSS) through missing field warning messages in Saved Search and Job Inspector on Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity Medium CVE-2025-20371Unauthenticated Blind Server Side Request Forgery (SSRF) in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity High CVE-2025-20367Reflected Cross-site Scripting (XSS) in '/app/search/table' endpoint through the 'dataset.command' parameter on Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity Medium CVE-2025-20366Improper Access Control in Background Job Submission in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity Medium CVE-2025-20369Extensible Markup Language (XML) External Entity Injection (XXE) through Dashboard label field on Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity Medium CVE-2025-20325Sensitive Information Disclosure in the SHCConfig logging channel in Clustered Deployments in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 07/07/2025 Severity Low CVE-2025-20300Improper Access Control Lets Low-Privilege Users Suppress Read-Only Alerts in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 07/07/2025 Severity Medium CVE-2025-20297Reflected Cross-Site Scripting (XSS) on Splunk Enterprise through dashboard PDF generation component Exploitation status Not known exploited Fix YesPublished 06/02/2025 Severity Medium CVE-2025-20232Risky Command Safeguards Bypass in “/app/search/search“ endpoint through “s“ parameter in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/26/2025 Severity Medium CVE-2025-20229Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/26/2025 Severity High CVE-2025-20228Maintenance mode state change of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF) in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/26/2025 Severity Medium CVE-2025-20227Information Disclosure through external content warning modal dialog box bypass in Splunk Enterprise Dashboard Studio Exploitation status Not known exploited Fix YesPublished 03/26/2025 Severity Medium CVE-2025-20226Risky command safeguards bypass in “/services/streams/search“ endpoint through “q“ parameter in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/26/2025 Severity Medium CVE-2024-53244Risky command safeguards bypass in “/en-US/app/search/report“ endpoint through “s“ parameter Exploitation status Not known exploited Fix YesPublished 12/10/2024 Severity Medium CVE-2024-53246Sensitive Information Disclosure through SPL commands Exploitation status Not known exploited Fix YesPublished 12/10/2024 Severity Medium CVE-2024-53245Information Disclosure due to Username Collision with a Role that has the same Name as the User Exploitation status Not known exploited Fix YesPublished 12/10/2024 Severity Low CVE-2024-45737Maintenance mode state change of App Key Value Store (KVStore) through Cross-Site Request Forgery (CSRF) Exploitation status Not known exploited Fix YesPublished 10/14/2024 Severity Medium CVE-2024-45732Low-privileged user could run search as nobody in SplunkDeploymentServerConfig app Exploitation status Public exploit Fix YesPublished 10/14/2024 Severity High CVE-2024-45736Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon Exploitation status Public exploit Fix YesPublished 10/14/2024 Severity Medium CVE-2024-45741Persistent Cross-Site Scripting (XSS) via props.conf on Splunk Enterprise Exploitation status Public exploit Fix YesPublished 10/14/2024 Severity Medium CVE-2024-45740Persistent Cross-Site Scripting (XSS) through Scheduled Views on Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 10/14/2024 Severity Medium CVE-2024-36997Persistent Cross-site Scripting (XSS) in conf-web/settings REST endpoint Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36993Persistent Cross-site Scripting (XSS) in Web Bulletin Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36995Low-privileged user could create experimental items Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36982Denial of Service through null pointer reference in “cluster/config” REST endpoint Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity High CVE-2024-36990Denial of Service (DoS) on the datamodel/web REST endpoint Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36992Persistent Cross-site Scripting (XSS) in Dashboard Elements Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36986Risky command safeguards bypass through Search ID query in Analytics Workspace Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36983Command Injection using External Lookups Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity High CVE-2024-36996Information Disclosure of user names Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36994Persistent Cross-site Scripting (XSS) in Dashboard Elements Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36989Low-privileged user could create notifications in Splunk Web Bulletin Messages Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-36987Insecure File Upload in the indexing/preview REST endpoint Exploitation status Not known exploited Fix YesPublished 07/01/2024 Severity Medium CVE-2024-29946Risky command safeguards bypass in Dashboard Examples Hub Exploitation status Not known exploited Fix YesPublished 03/27/2024 Severity High CVE-2023-32709Low-privileged User can View Hashed Default Splunk Password Exploitation status Not known exploited Fix YesPublished 06/01/2023 Severity Medium CVE-2023-32707‘edit_user’ Capability Privilege Escalation Exploitation status Not known exploited Fix YesPublished 06/01/2023 Severity High CVE-2023-32716Denial of Service via the 'dump' SPL command Exploitation status Not known exploited Fix YesPublished 06/01/2023 Severity Medium CVE-2023-32710Information Disclosure via the ‘copyresults’ SPL Command Exploitation status Not confirmed Fix YesPublished 06/01/2023 Severity Medium CVE-2023-32717Role-based Access Control (RBAC) Bypass on '/services/indexing/preview' REST Endpoint Can Overwrite Search Results Exploitation status Not confirmed Fix YesPublished 06/01/2023 Severity Medium CVE-2023-32706Denial Of Service due to Untrusted XML Tag in XML Parser within SAML Authentication Exploitation status Not known exploited Fix YesPublished 06/01/2023 Severity High CVE-2023-32708HTTP Response Splitting via the ‘rest’ SPL Command Exploitation status Not confirmed Fix YesPublished 06/01/2023 Severity High CVE-2023-22939SPL Command Safeguards Bypass via the ‘map’ SPL Command in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/14/2023 Severity High CVE-2023-22938Permissions Validation Failure in the ‘sendemail’ REST API Endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/14/2023 Severity Medium CVE-2023-22937Unnecessary File Extensions Allowed by Lookup Table Uploads in Splunk Enterprise Exploitation status Not confirmed Fix YesPublished 02/14/2023 Severity Medium CVE-2023-22933Persistent Cross-Site Scripting through the ‘module’ Tag in a View in Splunk Enterprise Exploitation status Not confirmed Fix YesPublished 02/14/2023 Severity High CVE-2023-22932Persistent Cross-Site Scripting through a Base64-encoded Image in a View in Splunk Enterprise Exploitation status Not confirmed Fix YesPublished 02/14/2023 Severity High CVE-2023-22936Authenticated Blind Server Side Request Forgery via the ‘search_listener’ Search Parameter in Splunk Enterprise Exploitation status Not confirmed Fix YesPublished 02/14/2023 Severity Medium CVE-2023-22941Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon Exploitation status Not known exploited Fix YesPublished 02/14/2023 Severity Medium CVE-2023-22931‘createrss’ External Search Command Overwrites Existing RSS Feeds in Splunk Enterprise Exploitation status Not confirmed Fix YesPublished 02/14/2023 Severity Medium CVE-2023-22935SPL Command Safeguards Bypass via the ‘display.page.search.patterns.sensitivity’ Search Parameter in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/14/2023 Severity High CVE-2023-22934SPL Command Safeguards Bypass via the ‘pivot’ SPL Command in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/14/2023 Severity High CVE-2023-22940SPL Command Safeguards Bypass via the ‘collect’ SPL Command Aliases in Splunk Enterprise Exploitation status Not confirmed Fix YesPublished 02/14/2023 Severity Medium CVE-2022-37438Information disclosure via the dashboard drilldown in Splunk Enterprise Exploitation status Not confirmed Fix YesPublished 08/16/2022 Severity Low CVE-2022-32152Splunk Enterprise lacked TLS cert validation for Splunk-to-Splunk communication by default Exploitation status Not confirmed Fix YesPublished 06/15/2022 Severity High