Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Splunk

155 known vulnerabilities

6
CRITICAL
47
HIGH
65
MEDIUM
5
LOW

Top Products

splunk 88 splunk cloud platform 24 soar 15 ai toolkit 12 splunk secure gateway 8 connect for kafka 4 enterprise security 2 on-call 1 model context protocol server 1
123 CVEs · Page 1/3
4.3
CVE-2026-76405

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" S

9.1
CVE-2026-76404

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands

7.4
CVE-2026-76403

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or a

8.2
CVE-2026-76402

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation

5.9
CVE-2026-76401

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation

5.9
CVE-2026-76400

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation

8.1
CVE-2026-76399

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled

4.3
CVE-2026-76398

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the

8.1
CVE-2026-76397

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant

7.5
CVE-2026-76396

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a sc

8.8
CVE-2026-76395

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the

8.3
CVE-2026-76394

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles c

5.9
CVE-2026-76393

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe

5.4
CVE-2026-76392

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain pre

8.3
CVE-2026-76391

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run search

8.1
CVE-2026-76388

In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role cou

8.1
CVE-2026-76387

In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the

4.3
CVE-2026-76370

In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational

2.7
CVE-2026-76369

In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Auto

2.7
CVE-2026-76368

In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view meta

4.0
CVE-2026-76367

In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript i

6.5
CVE-2026-76366

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (

6.5
CVE-2026-76365

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Str

6.5
CVE-2026-76364

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Str

6.5
CVE-2026-76363

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Quer

7.4
CVE-2026-76362

In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOA

2.7
CVE-2026-76361

In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../c

4.3
CVE-2026-76360

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to

6.5
CVE-2026-76359

In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal F

6.5
CVE-2026-76358

In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation

7.6
CVE-2026-76357

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the

8.1
CVE-2026-76356

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to a

7.5
CVE-2026-76355

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edg

8.1
CVE-2026-76354

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

5.4
CVE-2026-76353

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

8.8
CVE-2026-76352

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

8.8
CVE-2026-76351

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9,

8.8
CVE-2026-76350

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_searc

6.4
CVE-2026-76349

In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated use

3.8
CVE-2026-76348

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the

5.4
CVE-2026-76347

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9,

5.4
CVE-2026-76346

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s

6.0
CVE-2026-76345

In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage search head cluster

7.7
CVE-2026-76344

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

6.5
CVE-2026-76343

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

5.4
CVE-2026-76342

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s

5.4
CVE-2026-76341

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could s

5.3
CVE-2026-76340

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-s

5.4
CVE-2026-76339

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

8.1
CVE-2026-76338

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trus

Frequently Asked Questions

How many CVEs affect Splunk?

Splunk has 155 CVE records in our database, including 6 critical and 57 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Splunk vulnerabilities?

Splunk has 6 critical severity (CVSS 9.0+) and 57 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Splunk vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Splunk products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Splunk Vulnerabilities

CyberStrike scans your infrastructure for Splunk vulnerabilities and provides real-time remediation guidance.

Get Started