Vulnerabilidades em Splunk

283 resultados
Análise Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2026-76255MEDIUMRisky Command Safeguards Bypass through Splunk Web in Splunk EnterpriseEPSS 0.2%CVE-2025-20381MEDIUMSPL commands allowlist controls bypass in Splunk MCP Server app through "run_splunk_query" MCP toolEPSS 0.2%CVE-2024-23678HIGHDeserialization of Untrusted Data on Splunk Enterprise for Windows through Path Traversal from Separate Disk PartitionEPSS 0.2%CVE-2026-76361LOWServer-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAREPSS 0.2%CVE-2026-76368LOWMissing Authorization through Playbooks in Splunk SOAREPSS 0.2%CVE-2026-76263MEDIUMImproper Access Control through the REST API in Splunk EnterpriseEPSS 0.2%CVE-2026-20265MEDIUMInsecure Default Domain Allowlist in Splunk AI ToolkitEPSS 0.2%CVE-2026-76324MEDIUMStored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk EnterpriseEPSS 0.2%CVE-2026-76309MEDIUMStructured Query Language (SQL) Injection through the REST API in Splunk EnterpriseEPSS 0.2%CVE-2026-76374MEDIUMInformation Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOAREPSS 0.2%CVE-2026-76375MEDIUMInformation Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAREPSS 0.2%CVE-2024-36995MEDIUMLow-privileged user could create experimental itemsEPSS 0.2%CVE-2026-76342MEDIUMRisky Commands Safeguards Bypass through Splunk Web in Splunk EnterpriseEPSS 0.2%CVE-2026-76261MEDIUMInsecure Default Access Control List through the REST API in Splunk Secure GatewayEPSS 0.2%CVE-2026-76251HIGHMissing Authorization through REST API Endpoints in the Splunk App for Splunk Observability CloudEPSS 0.2%CVE-2026-76349MEDIUMSPL Injection through Splunk Web Form Tokens in Splunk EnterpriseEPSS 0.2%CVE-2026-76347MEDIUMServer-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure GatewayEPSS 0.2%CVE-2026-76328MEDIUMSPL Injection through Splunk Web in Splunk EnterpriseEPSS 0.2%CVE-2026-76327MEDIUMSPL Injection through Splunk Web in Splunk Secure GatewayEPSS 0.2%CVE-2026-76360MEDIUMInformation Disclosure through Missing Authorization in the Health REST API in Splunk SOAREPSS 0.2%