Vulnerabilidades en Splunk

283 resultados
Análisis Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2026-76326MEDIUMStored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Splunk EnterpriseEPSS 0.2%CVE-2026-76336HIGHImproper Access Control through the REST API in Splunk EnterpriseEPSS 0.2%CVE-2025-20324MEDIUMImproper Access Control in System Source Types Configuration in Splunk EnterpriseEPSS 0.2%CVE-2026-20258HIGHStored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk EnterpriseEPSS 0.2%CVE-2025-20378LOWOpen Redirect on Web Login endpoint in Splunk EnterpriseEPSS 0.2%CVE-2026-76396HIGHImproper Access Control through Scheduled Searches in Splunk AI ToolkitEPSS 0.2%CVE-2023-40597HIGHAbsolute Path Traversal in Splunk Enterprise Using runshellscript.pyEPSS 0.2%CVE-2026-20137LOWRisky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk EnterpriseEPSS 0.2%CVE-2026-76348LOWMissing Authorization in Search Head Cluster Member Controls in Splunk EnterpriseEPSS 0.2%CVE-2026-20298MEDIUMSensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk EnterpriseEPSS 0.2%CVE-2026-76323MEDIUMSPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk EnterpriseEPSS 0.2%CVE-2026-76331HIGHSPL Injection through the REST API in Splunk EnterpriseEPSS 0.2%CVE-2026-76256MEDIUMInformation Exposure through REST API Endpoints in Splunk Secure GatewayEPSS 0.2%CVE-2026-20164MEDIUMSensitive Information Disclosure through Improper Access Control in Splunk EnterpriseEPSS 0.2%CVE-2026-76341MEDIUMRisky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk EnterpriseEPSS 0.2%CVE-2025-20382LOWURL validation bypass through Views Dashboard in Splunk EnterpriseEPSS 0.2%CVE-2025-20228MEDIUMMaintenance mode state change of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF) in Splunk EnterpriseEPSS 0.2%CVE-2024-45737MEDIUMMaintenance mode state change of App Key Value Store (KVStore) through Cross-Site Request Forgery (CSRF)EPSS 0.2%CVE-2025-20373LOWSensitive Information Disclosure in “_internal“ index through Splunk Add-On for Palo Alto NetworksEPSS 0.2%CVE-2021-42743HIGHLocal privilege escalation via a default path in Splunk Enterprise WindowsEPSS 0.2%