Vulnerabilidades em Splunk

283 resultados
Análise Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2026-76369LOWPath Traversal through Automation Broker in Splunk SOAREPSS 0.3%CVE-2025-22621MEDIUMPrivilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAREPSS 0.3%CVE-2026-76260MEDIUMIncorrect Permission Assignment for Critical Resource through the REST API in Splunk EnterpriseEPSS 0.3%CVE-2026-76333HIGHStored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk EnterpriseEPSS 0.3%CVE-2026-76394HIGHMissing Authorization in Container and Connection Management through the REST API in Splunk AI ToolkitEPSS 0.3%CVE-2025-20300MEDIUMImproper Access Control Lets Low-Privilege Users Suppress Read-Only Alerts in Splunk EnterpriseEPSS 0.3%CVE-2025-20323MEDIUMMissing Access Control of Saved Searches in the Splunk Archiver appEPSS 0.3%CVE-2026-76352HIGHImproper Authorization through the REST API in Splunk EnterpriseEPSS 0.3%CVE-2023-4571HIGHUnauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)EPSS 0.3%CVE-2026-76397HIGHImproper Access Control in Experiment History through the REST API in Splunk AI ToolkitEPSS 0.3%CVE-2026-76325HIGHStored Cross-Site Scripting (XSS) through Splunk Web in Splunk EnterpriseEPSS 0.3%CVE-2026-76258MEDIUMUse of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure GatewayEPSS 0.2%CVE-2026-76388HIGHPrivilege Escalation through Search Macro Permissions in Splunk Enterprise SecurityEPSS 0.2%CVE-2026-76257MEDIUMMissing Authorization through REST API Endpoints in Splunk Secure GatewayEPSS 0.2%CVE-2026-76399HIGHIncorrect Permission Assignment for Scheduled Searches in Splunk AI ToolkitEPSS 0.2%CVE-2026-76354HIGHPath Traversal through Search Head Clustering in Splunk EnterpriseEPSS 0.2%CVE-2026-76332HIGHSPL Injection through Splunk Web in Splunk EnterpriseEPSS 0.2%CVE-2026-20202MEDIUMImproper Input Validation during User Account Creation in Splunk EnterpriseEPSS 0.2%CVE-2026-76330HIGHSPL Injection through Monitoring Console Forwarder Filters in Splunk EnterpriseEPSS 0.2%CVE-2026-76351HIGHServer-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure GatewayEPSS 0.2%