| CVE-2026-20253exploited | 9.8 | critical | splunk / splunk | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create | 87d ago |
| CVE-2026-76312 | 9.4 | critical | splunk / splunk | In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the H | 17d ago |
| CVE-2026-76311 | 9.4 | critical | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedde | 17d ago |
| CVE-2026-76310 | 9.4 | critical | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedde | 17d ago |
| CVE-2026-76404 | 9.1 | critical | splunk / model context protocol server | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary co | 17d ago |
| CVE-2026-20266 | 9.1 | critical | splunk / ai toolkit | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS com | 80d ago |
| CVE-2026-76395 | 8.8 | high | splunk / ai toolkit | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code o | 17d ago |
| CVE-2026-76352 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 17d ago |
| CVE-2026-76351 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3 | 17d ago |
| CVE-2026-76350 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule | 17d ago |
| CVE-2026-76335 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a | 17d ago |
| CVE-2026-76319 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold t | 17d ago |
| CVE-2026-76317 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 17d ago |
| CVE-2026-76316 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the | 17d ago |
| CVE-2026-76315 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 17d ago |
| CVE-2026-76314 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 17d ago |
| CVE-2026-76313 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 17d ago |
| CVE-2026-76259 | 8.8 | high | splunk / splunk | In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with acce | 17d ago |
| CVE-2026-76253 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule | 17d ago |
| CVE-2026-20251 | 8.8 | high | splunk / splunk | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3. | 87d ago |
| CVE-2026-76394 | 8.3 | high | splunk / ai toolkit | In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk r | 17d ago |
| CVE-2026-76391 | 8.3 | high | splunk / ai toolkit | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run | 17d ago |
| CVE-2026-20296 | 8.3 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 1 | 52d ago |
| CVE-2026-76402 | 8.2 | high | splunk / connect for kafka | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Represen | 17d ago |
| CVE-2026-76399 | 8.1 | high | splunk / ai toolkit | In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided sche | 17d ago |
| CVE-2026-76397 | 8.1 | high | splunk / ai toolkit | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all re | 17d ago |
| CVE-2026-76388 | 8.1 | high | splunk / enterprise security | In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security ro | 17d ago |
| CVE-2026-76387 | 8.1 | high | splunk / enterprise security | In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contai | 17d ago |
| CVE-2026-76356 | 8.1 | high | splunk / soar | In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted reques | 17d ago |
| CVE-2026-76354 | 8.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 17d ago |
| CVE-2026-76338 | 8.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to | 17d ago |
| CVE-2026-76331 | 8.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 17d ago |
| CVE-2026-76344 | 7.7 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "p | 17d ago |
| CVE-2026-76357 | 7.6 | high | splunk / soar | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path | 17d ago |
| CVE-2026-20252 | 7.6 | high | splunk / splunk | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 1 | 87d ago |
| CVE-2026-76396 | 7.5 | high | splunk / ai toolkit | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could caus | 17d ago |
| CVE-2026-76355 | 7.5 | high | splunk / splunk | In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained | 17d ago |
| CVE-2026-76262 | 7.5 | high | splunk / splunk | In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics fro | 17d ago |
| CVE-2026-76254 | 7.5 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could caus | 17d ago |
| CVE-2026-20239 | 7.5 | high | splunk / splunk | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2. | 108d ago |
| CVE-2026-76403 | 7.4 | high | splunk / connect for kafka | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could rea | 17d ago |
| CVE-2026-76362 | 7.4 | high | splunk / soar | In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splu | 17d ago |
| CVE-2026-76325 | 7.3 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role c | 17d ago |
| CVE-2026-76321 | 7.3 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could inject arbit | 17d ago |
| CVE-2026-20297 | 7.2 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions | 52d ago |
| CVE-2026-20163 | 7.2 | high | splunk / splunk | In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10 | 178d ago |
| CVE-2026-76336 | 7.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk role | 17d ago |
| CVE-2026-76333 | 7.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role c | 17d ago |
| CVE-2026-76332 | 7.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an aut | 17d ago |
| CVE-2026-76330 | 7.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an aut | 17d ago |
| CVE-2026-76251 | 7.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Sp | 17d ago |
| CVE-2026-20258 | 7.1 | high | splunk / splunk | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 1 | 87d ago |
| CVE-2026-20164 | 6.5 | medium | splunk / splunk | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10 | 178d ago |
| CVE-2026-20165 | 6.3 | medium | splunk / splunk | In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10 | 178d ago |
| CVE-2026-20162 | 6.3 | medium | splunk / splunk | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10. | 178d ago |
| CVE-2026-20166 | 5.4 | medium | splunk / splunk | In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1. | 178d ago |