Vulnerabilidades en Splunk

283 resultados
Análisis Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2026-76315HIGHCode Injection through Splunk Web Manager Configuration in Splunk EnterpriseEPSS 0.4%CVE-2022-43562LOWHost Header Injection in Splunk EnterpriseEPSS 0.4%CVE-2025-20366MEDIUMImproper Access Control in Background Job Submission in Splunk EnterpriseEPSS 0.4%CVE-2022-37437HIGHIngest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validationEPSS 0.4%CVE-2023-32710MEDIUMInformation Disclosure via the ‘copyresults’ SPL CommandEPSS 0.4%CVE-2023-22940MEDIUMSPL Command Safeguards Bypass via the ‘collect’ SPL Command Aliases in Splunk EnterpriseEPSS 0.4%CVE-2025-20389MEDIUMImproper Input Validation in "label" column field in Splunk Secure Gateway AppEPSS 0.4%CVE-2023-22937MEDIUMUnnecessary File Extensions Allowed by Lookup Table Uploads in Splunk EnterpriseEPSS 0.4%CVE-2025-20227MEDIUMInformation Disclosure through external content warning modal dialog box bypass in Splunk Enterprise Dashboard StudioEPSS 0.4%CVE-2026-20254MEDIUMInformation Disclosure through External Content Restriction Bypass in Splunk EnterpriseEPSS 0.4%CVE-2026-76345MEDIUMRemote Code Execution (RCE) through the REST API in Splunk EnterpriseEPSS 0.4%CVE-2023-40594MEDIUMDenial of Service (DoS) via the ‘printf’ Search FunctionEPSS 0.4%CVE-2023-22932HIGHPersistent Cross-Site Scripting through a Base64-encoded Image in a View in Splunk EnterpriseEPSS 0.4%CVE-2026-20240HIGHDenial of Service through coldToFrozen.sh Script in Splunk EnterpriseEPSS 0.4%CVE-2024-23677MEDIUMServer Response Disclosure in RapidDiag Salesforce.com Log FileEPSS 0.4%CVE-2025-20320MEDIUMDenial of Service (DoS) through “User Interface - Views“ configuration page in Splunk EnterpriseEPSS 0.4%CVE-2024-36986MEDIUMRisky command safeguards bypass through Search ID query in Analytics WorkspaceEPSS 0.4%CVE-2023-32709MEDIUMLow-privileged User can View Hashed Default Splunk PasswordEPSS 0.4%CVE-2024-45732HIGHLow-privileged user could run search as nobody in SplunkDeploymentServerConfig appEPSS 0.4%CVE-2023-46230HIGHSensitive Information Disclosure to Internal Log Files in Splunk Add-on BuilderEPSS 0.4%