splunk
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting splunk.
- CVE-2026-20298Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise5.3
- CVE-2026-20296SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise8.3
- CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise7.2
- CVE-2026-20266OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit9.1
- CVE-2026-20265Insecure Default Domain Allowlist in Splunk AI Toolkit4.3
- CVE-2026-20258Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise7.1
- CVE-2026-20253Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk EnterpriseKEV9.8
- CVE-2026-20260Log Injection through HTTP Request Paths in Splunk SOAR4.3
- CVE-2026-20252Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise7.6
- CVE-2026-20257Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise5.7
- CVE-2026-20259Improper Access Control in Splunk Enterprise5.5
- CVE-2026-20251Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway8.8
- CVE-2026-20255Improper Input Validation through Classic Dashboards in Splunk Enterprise5.7
- CVE-2026-20254Information Disclosure through External Content Restriction Bypass in Splunk Enterprise5.7
- CVE-2026-20256Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise5.7