Vulnerabilidades em Splunk

283 resultados
Análise Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2026-76314HIGHRemote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk EnterpriseEPSS 0.7%CVE-2022-43561MEDIUMPersistent Cross-Site Scripting in “Save Table” Dialog in Splunk EnterpriseEPSS 0.7%CVE-2022-26070MEDIUMError message discloses internal pathEPSS 0.6%CVE-2022-43565HIGHRisky command safeguards bypass via ‘tstats command JSON in Splunk EnterpriseEPSS 0.6%CVE-2022-43563HIGHRisky command safeguards bypass via rex search command field names in Splunk EnterpriseEPSS 0.6%CVE-2026-20266CRITICALOS Command Injection in the btool Configuration Helper in Splunk AI ToolkitEPSS 0.6%CVE-2023-32716MEDIUMDenial of Service via the 'dump' SPL commandEPSS 0.6%CVE-2023-22935HIGHSPL Command Safeguards Bypass via the ‘display.page.search.patterns.sensitivity’ Search Parameter in Splunk EnterpriseEPSS 0.6%CVE-2023-32706HIGHDenial Of Service due to Untrusted XML Tag in XML Parser within SAML AuthenticationEPSS 0.6%CVE-2021-3422HIGHIndexer denial-of-service via malformed S2S requestEPSS 0.6%CVE-2023-22939HIGHSPL Command Safeguards Bypass via the ‘map’ SPL Command in Splunk EnterpriseEPSS 0.6%CVE-2023-40593MEDIUMDenial of Service (DoS) in Splunk Enterprise Using a Malformed SAML RequestEPSS 0.6%CVE-2026-20297HIGHPath Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk EnterpriseEPSS 0.6%CVE-2023-40592HIGHReflected Cross-site Scripting (XSS) on "/app/search/table" web endpointEPSS 0.6%CVE-2026-76404CRITICALRemote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server appEPSS 0.6%CVE-2025-20370MEDIUMDenial of Service (DoS) through Multiple LDAP Bind Requests in Splunk EnterpriseEPSS 0.6%CVE-2024-36997MEDIUMPersistent Cross-site Scripting (XSS) in conf-web/settings REST endpointEPSS 0.5%CVE-2024-45736MEDIUMImproperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk DaemonEPSS 0.5%CVE-2024-45731HIGHPotential Remote Command Execution (RCE) through arbitrary file write to Windows system root directory when Splunk Enterprise for Windows is installed on a separate diskEPSS 0.5%CVE-2024-22165MEDIUMDenial of Service in Splunk Enterprise Security of the Investigations manager through Investigation creationEPSS 0.5%