Vulnerabilidades em Splunk

283 resultados
Análise Vexday

O portfólio de vulnerabilidades do Splunk soma 170 CVEs catalogadas, com uma taxa de exploração ativa que supera a média geral do catálogo em 1,3×, sinal de que as falhas nessa plataforma atraem atenção real de agentes maliciosos. O CVE-2026-20253, único item confirmado no CISA KEV, apresenta EPSS de 0,8817 — indicando altíssima probabilidade de exploração —, e deve ser tratado como prioridade imediata de correção. O tipo de falha mais recorrente, CWE-79 (cross-site scripting), sugere que superfícies de interface com o usuário seguem sendo o vetor mais frequente no produto. A chegada de 19 novas CVEs nos últimos 90 dias, somada à existência de 3 vulnerabilidades com PoC pública, reforça a necessidade de ciclos curtos de patching e monitoramento contínuo do ambiente.

CVE-2026-76317HIGHPath Traversal through the Lookup Configuration REST API in Splunk EnterpriseEPSS 0.4%CVE-2025-20384MEDIUMUnauthenticated Log Injection in Splunk EnterpriseEPSS 0.4%CVE-2026-20144MEDIUMSensitive Information Disclosure in ''_internal'' index in Splunk EnterpriseEPSS 0.4%CVE-2026-76319HIGHRemote Code Execution (RCE) through Federated Search in Splunk EnterpriseEPSS 0.4%CVE-2024-23675MEDIUMSplunk App Key Value Store (KV Store) Improper Handling of Permissions Leads to KV Store Collection DeletionEPSS 0.4%CVE-2023-22936MEDIUMAuthenticated Blind Server Side Request Forgery via the ‘search_listener’ Search Parameter in Splunk EnterpriseEPSS 0.4%CVE-2024-36993MEDIUMPersistent Cross-site Scripting (XSS) in Web BulletinEPSS 0.4%CVE-2026-76262HIGHExposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk EnterpriseEPSS 0.4%CVE-2026-76310CRITICALImproper Access Control through Embedded Report REST API Requests in Splunk EnterpriseEPSS 0.4%CVE-2026-76311CRITICALImproper Access Control in Embedded Report Dispatch Archives in Splunk EnterpriseEPSS 0.4%CVE-2024-45740MEDIUMPersistent Cross-Site Scripting (XSS) through Scheduled Views on Splunk EnterpriseEPSS 0.4%CVE-2024-53245LOWInformation Disclosure due to Username Collision with a Role that has the same Name as the UserEPSS 0.4%CVE-2026-76312CRITICALImproper Access Control through Embedded Reports in Splunk EnterpriseEPSS 0.4%CVE-2026-76356HIGHAuthentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAREPSS 0.4%CVE-2023-22931MEDIUM‘createrss’ External Search Command Overwrites Existing RSS Feeds in Splunk EnterpriseEPSS 0.4%CVE-2023-32717MEDIUMRole-based Access Control (RBAC) Bypass on '/services/indexing/preview' REST Endpoint Can Overwrite Search ResultsEPSS 0.4%CVE-2026-76359MEDIUMPath Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAREPSS 0.4%CVE-2026-20256MEDIUMImproper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk EnterpriseEPSS 0.4%CVE-2026-76358MEDIUMPath Traversal through App Installation Tar Extraction in Splunk SOAREPSS 0.4%CVE-2025-20368MEDIUMStored Cross-Site Scripting (XSS) through missing field warning messages in Saved Search and Job Inspector on Splunk EnterpriseEPSS 0.4%