splunk
99 known vulnerabilities affecting splunk products.
Products
splunk 66
soar 15
ai_toolkit 10
splunk_secure_gateway 7
splunk_cloud_platform 5
connect_for_kafka 4
enterprise_security 2
model_context_protocol_server 1
on-call 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-20253 | Act now | 96.9% | 9.8 | ● | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an… |
| CVE-2026-76314 | Medium | 0.7% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-20297 | Medium | 0.6% | 7.2 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, … | |
| CVE-2026-76404 | Medium | 0.6% | 9.1 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splu… | |
| CVE-2026-76313 | Medium | 0.5% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76395 | Medium | 0.5% | 8.8 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk r… | |
| CVE-2026-20239 | Medium | 0.5% | 7.5 | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform… | |
| CVE-2026-76315 | Medium | 0.4% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76317 | Medium | 0.4% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76319 | Medium | 0.4% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-pr… | |
| CVE-2026-76262 | Medium | 0.4% | 7.5 | In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could r… | |
| CVE-2026-76310 | Medium | 0.4% | 9.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut… | |
| CVE-2026-76311 | Medium | 0.4% | 9.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut… | |
| CVE-2026-76312 | Medium | 0.4% | 9.4 | In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unaut… | |
| CVE-2026-76356 | Medium | 0.4% | 8.1 | In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the sou… | |
| CVE-2026-76355 | Medium | 0.4% | 7.5 | In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could r… | |
| CVE-2026-76253 | Medium | 0.4% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user t… | |
| CVE-2026-76391 | Medium | 0.3% | 8.3 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" … | |
| CVE-2026-76321 | Medium | 0.3% | 7.3 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut… | |
| CVE-2026-76335 | Medium | 0.3% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authe… | |
| CVE-2026-76357 | Medium | 0.3% | 7.6 | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned… | |
| CVE-2026-76254 | Medium | 0.3% | 7.5 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, … | |
| CVE-2026-76316 | Medium | 0.3% | 8.8 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unaut… | |
| CVE-2026-76402 | Medium | 0.3% | 8.2 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who ca… | |
| CVE-2026-76344 | Medium | 0.3% | 7.7 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76387 | Medium | 0.3% | 8.1 | In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk En… | |
| CVE-2026-76350 | Medium | 0.3% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user t… | |
| CVE-2026-76338 | Medium | 0.3% | 8.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut… | |
| CVE-2026-76333 | Medium | 0.3% | 7.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76394 | Medium | 0.3% | 8.3 | In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not ho… | |
| CVE-2026-76352 | Medium | 0.3% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76397 | Medium | 0.3% | 8.1 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk r… | |
| CVE-2026-76325 | Medium | 0.3% | 7.3 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76388 | Medium | 0.2% | 8.1 | In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_ana… | |
| CVE-2026-76399 | Medium | 0.2% | 8.1 | In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk r… | |
| CVE-2026-76354 | Medium | 0.2% | 8.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76330 | Medium | 0.2% | 7.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut… | |
| CVE-2026-76332 | Medium | 0.2% | 7.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut… | |
| CVE-2026-76351 | Medium | 0.2% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splu… | |
| CVE-2026-76336 | Medium | 0.2% | 7.1 | In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold … | |
| CVE-2026-76396 | Medium | 0.2% | 7.5 | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the sch… | |
| CVE-2026-76331 | Medium | 0.2% | 8.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w… | |
| CVE-2026-76251 | Medium | 0.2% | 7.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does … | |
| CVE-2026-76403 | Medium | 0.2% | 7.4 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positi… | |
| CVE-2026-20296 | Medium | 0.2% | 8.3 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splu… | |
| CVE-2026-76362 | Medium | 0.2% | 7.4 | In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or … | |
| CVE-2026-76259 | Medium | 0.1% | 8.8 | In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, … | |
| CVE-2026-76345 | Low | 0.4% | 6.0 | In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk … | |
| CVE-2026-20240 | Low | 0.4% | 6.5 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splu… | |
| CVE-2026-76358 | Low | 0.4% | 6.5 | In Splunk SOAR versions below 8.6.0, a user with app-install privileges could us… |
Page 1 of 2
Next →