Vulnerabilidades en Splunk

283 resultados
Análisis Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2024-36987MEDIUMInsecure File Upload in the indexing/preview REST endpointEPSS 0.3%CVE-2025-20298HIGHIncorrect permission assignment on Universal Forwarder for Windows during new installation or upgradeEPSS 0.3%CVE-2026-76390MEDIUMInformation Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security CloudEPSS 0.3%CVE-2026-76322MEDIUMSPL Injection through Dashboard Studio Search Query Options in Splunk EnterpriseEPSS 0.3%CVE-2026-76363MEDIUMStructured Query Language Injection through the REST API in Splunk SOAREPSS 0.3%CVE-2023-3997HIGHUnauthenticated Log Injection In Splunk SOAREPSS 0.3%CVE-2024-53246MEDIUMSensitive Information Disclosure through SPL commandsEPSS 0.3%CVE-2026-76400MEDIUMDenial of Service (DoS) through the REST API in Splunk Connect for KafkaEPSS 0.3%CVE-2026-76364MEDIUMStructured Query Language (SQL) Injection through Custom Function Results in Splunk SOAREPSS 0.3%CVE-2026-76401MEDIUMRegular Expression Denial of Service (DoS) through the REST API in Splunk Connect for KafkaEPSS 0.3%CVE-2026-76387HIGHSPL Injection through the REST API in Splunk Enterprise SecurityEPSS 0.3%CVE-2026-76353MEDIUMPath Traversal through Knowledge Bundle Replication in Splunk EnterpriseEPSS 0.3%CVE-2025-20379LOWRisky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk EnterpriseEPSS 0.3%CVE-2026-76350HIGHImproper Privilege Management through PDF Attachments for Email Alert Actions in Splunk EnterpriseEPSS 0.3%CVE-2026-20205HIGHSensitive Information Disclosure in ''_internal'' index in Splunk MCP Server appEPSS 0.3%CVE-2024-36989MEDIUMLow-privileged user could create notifications in Splunk Web Bulletin MessagesEPSS 0.3%CVE-2025-20385LOWStored Cross-Site scripting (XSS) through Anchor Tag "href" in Navigation Bar Collections in Splunk EnterpriseEPSS 0.3%CVE-2026-76343MEDIUMStructured Query Language (SQL) Injection through the REST API in Splunk EnterpriseEPSS 0.3%CVE-2026-76338HIGHImproper Authentication through REST API Distributed Search Token Requests in Splunk EnterpriseEPSS 0.3%CVE-2026-76340MEDIUMMissing Authorization for Reloading Token-Signing Keys through the REST API in Splunk EnterpriseEPSS 0.3%