[CIVN-2026-0421] Multiple Vulnerabilities in Splunk Products

By Published On: August 25, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Splunk Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Splunk Enterprise 

Versions prior to 10.4.2 

Versions prior to 10.2.6 

Versions prior to 10.0.9 

Versions prior to 9.4.14

Overview


Multiple vulnerabilities have been reported in Splunk products, which could allow an attacker to bypass authorization and authentication controls, execute arbitrary code, inject SPL/SQL commands, perform path traversal and server-side request forgery (SSRF), access sensitive information, conduct cross-site scripting (XSS) attacks, and escalate privileges on the targeted system.


Target Audience:

All organizations and individuals using Splunk products.


Risk Assessment:

Risk of unauthorized system access, remote code execution, data exfiltration, privilege escalation, information disclosure, server-side request forgery (SSRF), cross-site scripting (XSS), and compromise of the confidentiality, integrity, and availability of affected Splunk environments.


Impact Assessment:

Potential for unauthorized access, sensitive information disclosure, data exfiltration, arbitrary code execution, privilege escalation, SSRF attacks, security control bypass, and stored cross-site scripting (XSS).


Description


Splunk is a platform used for searching, monitoring, and analyzing machine-generated data in real time. It collects, indexes, and correlates large volumes of data generated by applications, servers, networks, and other infrastructure components.


These vulnerabilities exist in Splunk products due to improper access control and authorization, insufficient authentication mechanisms, improper input validation and sanitization, inadequate security safeguards, privilege management weaknesses, SPL/SQL injection flaws, path traversal, server-side request forgery (SSRF), cross-site scripting (XSS), and cross-site request forgery (CSRF) conditions within affected components.


Successful exploitation of these vulnerabilities could allow an attacker to bypass authorization and authentication controls, execute arbitrary code, inject SPL/SQL commands, perform path traversal and server-side request forgery (SSRF), access sensitive information, conduct cross-site scripting (XSS) attacks, and escalate privileges on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://advisory.splunk.com/advisories/SVD-2026-0801



Vendor Information


Splunk

https://www.splunk.com/


References


Splunk

https://advisory.splunk.com/advisories/SVD-2026-0801


CVE Name

CVE-2026-76251

CVE-2026-76252

CVE-2026-76253

CVE-2026-76254

CVE-2026-76255

CVE-2026-76256

CVE-2026-76257

CVE-2026-76258

CVE-2026-76259

CVE-2026-76260

CVE-2026-76261

CVE-2026-76262

CVE-2026-76263

CVE-2026-76309

CVE-2026-76310

CVE-2026-76311

CVE-2026-76312

CVE-2026-76313

CVE-2026-76314

CVE-2026-76315

CVE-2026-76316

CVE-2026-76317

CVE-2026-76318

CVE-2026-76319

CVE-2026-76320

CVE-2026-76321

CVE-2026-76322

CVE-2026-76323

CVE-2026-76324

CVE-2026-76325

CVE-2026-76326

CVE-2026-76327

CVE-2026-76328

CVE-2026-76329

CVE-2026-76330

CVE-2026-76331

CVE-2026-76332

CVE-2026-76333

CVE-2026-76334

CVE-2026-76335

CVE-2026-76336

CVE-2026-76337

CVE-2026-76338

CVE-2026-76339

CVE-2026-76340

CVE-2026-76341

CVE-2026-76342

CVE-2026-76343

CVE-2026-76344

CVE-2026-76345

CVE-2026-76346

CVE-2026-76347

CVE-2026-76348

CVE-2026-76349

CVE-2026-76350

CVE-2026-76351

CVE-2026-76352

CVE-2026-76353

CVE-2026-76354

CVE-2026-76355




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqNpqoACgkQ3jCgcSdc

ys8rwBAAmK9hl+/uM0WOhGE/yG2rDMgqVwdmWF0DvFaPP7EY/1lmjs93uibrT3Ka

jwojCcsG90JTR0RLr8eyMh5ujb38tuLtEpTTYRsiuTH8FQUP+AiWEbHHiu+rxiRf

O9QoyRcxXF+KK4LM4yC42cGqzSPDFyX8Mtx7Ejj99FM4LO25/r5P2NncXoPYxv/C

t7xG4QVrJOzaW2MO4pKEo8RZJb7vW8kzTLQIna1D1xuoZG3Uxq1nWju5j5uRXrlp

YoIhgWkcH411wl7ee4cqrjT1evI0bgUKBA615ushsTNH+WM/LQswa3aHoG47QSoS

hATGCGOfFDa1bd+1PkHdkSvkFGrHNXb3dNLo55cMn9TSM7j1wLdMFJsfGJOnme81

d7S0JzcNZrbKqDU4oNS9IALrpv/5DmW0kz0XwLLNErcdYMy9GPNZon88NXZ3iPBq

ftm9rboisQtrvf6ABGq3RCPEbnzBetZwkKXlFvnDGE6mOcOKi721qMEabSqFoTK0

2JSINoV1UWEz7kFwz7V5lAAbfCorzN5wj8j0WwFXDMPs2qIEGXBQlUjffVEYNFWv

osZmsghdvWr6x749sPxA0zDuPwGLfR6qAlWqkerSLl9BtsnQRPTEuiUHYXc4SQAI

QANyAAgQjA8T2axYP83bSU5K+DgFpJQYmmMznYXBnXCrQyGUFy4=

=xkeN

—–END PGP SIGNATURE—–

Share this article