CVE-2026-76355Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76354Path Traversal through Search Head Clustering in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76353Path Traversal through Knowledge Bundle Replication in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76352Improper Authorization through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76351Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76350Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76349SPL Injection through Splunk Web Form Tokens in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76348Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Low CVE-2026-76347Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76346Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76345Remote Code Execution (RCE) through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76344Path Traversal through the Search Dispatch REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76343Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76342Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76341Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76340Missing Authorization for Reloading Token-Signing Keys through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76339SPL Injection through the geostats Command in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76338Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76337Path Traversal through Splunk Web Static File Serving in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76336Improper Access Control through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76335Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76334SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76333Stored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76332SPL Injection through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76331SPL Injection through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76330SPL Injection through Monitoring Console Forwarder Filters in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76329SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76328SPL Injection through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76327SPL Injection through Splunk Web in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76326Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76325Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76324Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76323SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76322SPL Injection through Dashboard Studio Search Query Options in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76321SPL Injection through Nearby Event Searches in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76320SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76319Remote Code Execution (RCE) through Federated Search in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76318Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76317Path Traversal through the Lookup Configuration REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76316Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76315Code Injection through Splunk Web Manager Configuration in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76314Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76313Remote Code Execution (RCE) through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76312Improper Access Control through Embedded Reports in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Critical CVE-2026-76311Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Critical CVE-2026-76310Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Critical CVE-2026-76309Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76263Improper Access Control through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76262Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76261Insecure Default Access Control List through the REST API in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76260Incorrect Permission Assignment for Critical Resource through the REST API in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76259Improper Privilege Management on the Management Port in Splunk Enterprise for Windows Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76258Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76257Missing Authorization through REST API Endpoints in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76256Information Exposure through REST API Endpoints in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76255Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76254SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76253Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-76252Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity Medium CVE-2026-76251Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability Cloud Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-20298Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 07/15/2026 Severity Medium CVE-2026-20296SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 07/15/2026 Severity High CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 07/15/2026 Severity High CVE-2026-20258Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity High CVE-2026-20253Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise Exploitation status KEV Fix YesPublished 06/10/2026 Severity Critical CVE-2026-20252Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity High CVE-2026-20257Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20259Improper Access Control in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20255Improper Input Validation through Classic Dashboards in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20251Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity High CVE-2026-20254Information Disclosure through External Content Restriction Bypass in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20256Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 06/10/2026 Severity Medium CVE-2026-20239Sensitive Information Disclosure through Log Files in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity High CVE-2026-20240Denial of Service through coldToFrozen.sh Script in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity High CVE-2026-20203Improper Access Control in Data Model Acceleration in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity Medium CVE-2026-20204Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity High CVE-2026-20202Improper Input Validation during User Account Creation in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity Medium CVE-2026-20163Remote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity High CVE-2026-20162Stored Cross-Site Scripting (XSS) through Path Traversal in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity Medium CVE-2026-20166Sensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity Medium CVE-2026-20164Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity Medium CVE-2026-20165Sensitive Information Disclosure in MongoClient logging channel in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 03/11/2026 Severity Medium CVE-2026-20142Sensitive Information Disclosure in "_internal" index in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Medium CVE-2026-20138Sensitive Information Disclosure in "_internal" index in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Medium CVE-2026-20139Client-Side Denial of Service (DoS) through ''/splunkd/__raw/services/authentication/users/username'' REST API endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Medium CVE-2026-20144Sensitive Information Disclosure in ''_internal'' index in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Medium CVE-2026-20141Improper Access Control in Splunk Monitoring Console App Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Medium CVE-2026-20137Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 02/18/2026 Severity Low CVE-2025-20388Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Low CVE-2025-20389Improper Input Validation in "label" column field in Splunk Secure Gateway App Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Medium CVE-2025-20387Incorrect permissions assignment on Splunk Universal Forwarder for Windows during new installation or upgrade Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity High CVE-2025-20383Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Medium CVE-2025-20384Unauthenticated Log Injection in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Medium CVE-2025-20386Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity High CVE-2025-20385Stored Cross-Site scripting (XSS) through Anchor Tag "href" in Navigation Bar Collections in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Low CVE-2025-20382URL validation bypass through Views Dashboard in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 12/03/2025 Severity Low CVE-2025-20379Risky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 11/12/2025 Severity Low CVE-2025-20378Open Redirect on Web Login endpoint in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 11/12/2025 Severity Low CVE-2025-20368Stored Cross-Site Scripting (XSS) through missing field warning messages in Saved Search and Job Inspector on Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity Medium CVE-2025-20371Unauthenticated Blind Server Side Request Forgery (SSRF) in Splunk Enterprise Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity High