Vulnerabilidades en Splunk

283 resultados
Análisis Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2023-32713HIGHLocal Privilege Escalation via the ‘streamfwd’ program in Splunk App for StreamEPSS 0.3%CVE-2024-23676MEDIUMSensitive Information Disclosure of Index Metrics through “mrollup” SPL CommandEPSS 0.3%CVE-2026-20238MEDIUMImproper Access Control through Role Inheritance in Splunk AI Toolkit appEPSS 0.3%CVE-2023-22943MEDIUMModular Input REST API Requests Connect via HTTP after Certificate Validation Failure in Splunk Add-on Builder and Splunk CloudConnect SDKEPSS 0.3%CVE-2025-20230MEDIUMMissing Access Control and Incorrect Ownership of Data in App Key Value Store (KVStore) collections in the Splunk Secure Gateway AppEPSS 0.3%CVE-2023-32715MEDIUMSelf Cross-Site Scripting (XSS) on Splunk App for Lookup File EditingEPSS 0.3%CVE-2026-76254HIGHSPL Command Safeguards Bypass through Splunk Web in Splunk EnterpriseEPSS 0.3%CVE-2026-76365MEDIUMStructured Query Language (SQL) Injection through Custom Lists in Splunk SOAREPSS 0.3%CVE-2024-36992MEDIUMPersistent Cross-site Scripting (XSS) in Dashboard ElementsEPSS 0.3%CVE-2025-20369MEDIUMExtensible Markup Language (XML) External Entity Injection (XXE) through Dashboard label field on Splunk EnterpriseEPSS 0.3%CVE-2026-76372MEDIUMIncorrect Permission Assignment through Safe Mode in Nmap Scanner for Splunk SOAREPSS 0.3%CVE-2025-20383MEDIUMImproper access control through push notifications for reports and alerts in Splunk Secure Gateway appEPSS 0.3%CVE-2024-36994MEDIUMPersistent Cross-site Scripting (XSS) in Dashboard ElementsEPSS 0.3%CVE-2026-76337MEDIUMPath Traversal through Splunk Web Static File Serving in Splunk EnterpriseEPSS 0.3%CVE-2026-76316HIGHStored SPL Injection through Deployment Server Broker Registration in Splunk EnterpriseEPSS 0.3%CVE-2026-76402HIGHServer-Side Request Forgery (SSRF) through the REST API in Splunk Connect for KafkaEPSS 0.3%CVE-2026-76344HIGHPath Traversal through the Search Dispatch REST API in Splunk EnterpriseEPSS 0.3%CVE-2024-53243MEDIUMInformation Disclosure in Mobile Alert Responses in Splunk Secure GatewayEPSS 0.3%CVE-2026-20257MEDIUMImproper Input Validation through Classic Dashboard CSS in Splunk EnterpriseEPSS 0.3%CVE-2026-76366MEDIUMInformation Disclosure through the REST API in Splunk SOAREPSS 0.3%