Vulnerabilidades en Splunk

283 resultados
Análisis Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2022-37438LOWInformation disclosure via the dashboard drilldown in Splunk EnterpriseEPSS 0.5%CVE-2025-20231HIGHSensitive Information Disclosure in Splunk Secure Gateway AppEPSS 0.5%CVE-2025-0367MEDIUMRegular Expression Denial of Service (ReDoS) in Splunk Supporting Add-on for Active Directory (SA-ldapsearch)EPSS 0.5%CVE-2024-45739MEDIUMSensitive information disclosure in AdminManager logging channelEPSS 0.5%CVE-2026-76313HIGHRemote Code Execution (RCE) through the REST API in Splunk EnterpriseEPSS 0.5%CVE-2024-36982HIGHDenial of Service through null pointer reference in “cluster/config” REST endpointEPSS 0.5%CVE-2025-20386HIGHIncorrect permission assignment on Splunk Enterprise for Windows during new installation or upgradeEPSS 0.5%CVE-2025-20387HIGHIncorrect permissions assignment on Splunk Universal Forwarder for Windows during new installation or upgradeEPSS 0.5%CVE-2026-76395HIGHRemote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI ToolkitEPSS 0.5%CVE-2026-20239HIGHSensitive Information Disclosure through Log Files in Splunk EnterpriseEPSS 0.5%CVE-2024-45738MEDIUMSensitive information disclosure in REST_Calls logging channelEPSS 0.5%CVE-2023-46231HIGHSession Token Disclosure to Internal Log Files in Splunk Add-on BuilderEPSS 0.5%CVE-2023-46213MEDIUMCross-site Scripting (XSS) on “Show Syntax Highlighted” View in Search PageEPSS 0.5%CVE-2024-53244MEDIUMRisky command safeguards bypass in “/en-US/app/search/report“ endpoint through “s“ parameterEPSS 0.5%CVE-2025-20371HIGHUnauthenticated Blind Server Side Request Forgery (SSRF) in Splunk EnterpriseEPSS 0.5%CVE-2025-20232MEDIUMRisky Command Safeguards Bypass in “/app/search/search“ endpoint through “s“ parameter in Splunk EnterpriseEPSS 0.5%CVE-2025-20226MEDIUMRisky command safeguards bypass in “/services/streams/search“ endpoint through “q“ parameter in Splunk EnterpriseEPSS 0.5%CVE-2026-20163HIGHRemote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk EnterpriseEPSS 0.5%CVE-2024-22164MEDIUMDenial of Service of an Investigation in Splunk Enterprise Security through Investigation attachmentsEPSS 0.5%CVE-2025-20319MEDIUMRemote Command Execution through Scripted Input Files in Splunk EnterpriseEPSS 0.4%