SecAlerts
Splunk logo

Splunk

Security Risk Profile

48
/100
medium

Security Risk Score

Comprehensive risk assessment based on 294 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 23, 2010 to present

294
Total CVEs
132
Critical+High
4
Exploited
93
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
93
Critical/High
Risk Level
48/100
medium
⚠️ 4 Active Exploits📈 3 in Last 30 Days

Severity Distribution

Critical
19
High
113
Medium
145
Low
11

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
9

Age Distribution

Common Weaknesses (CWE)

1
XSS
47
2
Input Validation
41
3
Infoleak
29
4
Path Traversal
16
5
CSRF
7

Most Affected Products

1. Splunk splunk1271
2. Splunk Splunk Cloud Platform301
3. Splunk Universal Forwarder181
4. NetApp H300s Firmware72
5. NetApp H700s Firmware72

Recent Vulnerabilities

See more →
CVE-2026-20298
CVSS 6.5medium

Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise

7/15/2026🔧 No Patch
CVE-2026-20296
CVSS 8.3high

SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise

7/15/2026🔧 No Patch
CVE-2026-20297
CVSS 7.2high

Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise

7/15/2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1ua3npz/cisa_adds_splunk_enterprise_rce_cve202620253_to/
unknown

CISA Adds Splunk Enterprise RCE (CVE-2026-20253) to KEV - CVSS 9.8. How are your SOCs handling the PostgreSQL sidecar mitigation?

6/19/2026🔧 No Patch
bleepingcomputer-20260619103958
unknown

CISA: Splunk Enterprise flaw actively exploited, patch by Sunday

6/19/2026⚠ Exploited🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1u9t7g7/splunk_enterprise_vulnerability_exploited_in/
unknown

Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

6/19/2026🔧 No Patch
CVE-2026-20266
CVSS 9.1critical

OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit

6/17/2026🔧 No Patch
CVE-2026-20265
CVSS 4.3medium

Insecure Default Domain Allowlist in Splunk AI Toolkit

6/17/2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1u4rpju/splunk_enterprise_had_an_unauthenticated_rce/
unknown

Splunk Enterprise had an unauthenticated RCE sitting in your security stack

6/13/2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1u46xf9/why_use_applevel_auth_when_every_database_has/
unknown

Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs

6/12/2026🔧 No Patch

Monitor Splunk in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.