Where
-Infinity
0

Splunk splunkSensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise

Risk 38
Severity
6.5
First published (updated )

Splunk splunkSPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise

Risk 67
Severity
8.3
First published (updated )

Splunk splunkPath Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise

Risk 66
Severity
7.2
First published (updated )

CISA Adds Splunk Enterprise RCE (CVE-2026-20253) to KEV - CVSS 9.8. How are your SOCs handling the PostgreSQL sidecar mitigation?

First published (updated )
Social
reddit

BleepingComputerCISA: Splunk Enterprise flaw actively exploited, patch by Sunday

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

First published (updated )
Social
reddit

Splunk Splunk AI ToolkitOS Command Injection in the btool Configuration Helper in Splunk AI Toolkit

Risk 72
Severity
9.1
First published (updated )

Splunk Splunk AI ToolkitInsecure Default Domain Allowlist in Splunk AI Toolkit

Risk 22
Severity
4.3
First published (updated )

Splunk Enterprise had an unauthenticated RCE sitting in your security stack

First published (updated )
Social
reddit

Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs

First published (updated )
Social
reddit
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs

First published (updated )
Social
reddit

Splunk Splunk Cloud PlatformStored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise

Risk 65
Severity
7.1
First published (updated )

Splunk splunkSplunk Enterprise Missing Authentication for Critical Function Vulnerability

Risk 99
Severity
9.8
First published (updated )

Splunk Splunk SOARLog Injection through HTTP Request Paths in Splunk SOAR

Risk 22
Severity
4.3
First published (updated )

Splunk Splunk Cloud PlatformServer-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise

Risk 58
Severity
7.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Splunk Splunk Cloud PlatformImproper Input Validation through Classic Dashboard CSS in Splunk Enterprise

Risk 33
Severity
5.7
First published (updated )

Splunk Splunk Cloud PlatformImproper Access Control in Splunk Enterprise

Risk 39
Severity
5.5
First published (updated )

Splunk Splunk Cloud PlatformRemote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway

Risk 79
Severity
8.8
First published (updated )

Splunk Splunk Cloud PlatformImproper Input Validation through Classic Dashboards in Splunk Enterprise

Risk 33
Severity
5.7
First published (updated )

Splunk Splunk Cloud PlatformInformation Disclosure through External Content Restriction Bypass in Splunk Enterprise

Risk 33
Severity
5.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Splunk Splunk Cloud PlatformImproper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise

Risk 33
Severity
5.7
First published (updated )

Splunk Splunk AI ToolkitImproper Access Control through Role Inheritance in Splunk AI Toolkit app

Risk 38
Severity
6.5
First published (updated )

Splunk Splunk Cloud PlatformSensitive Information Disclosure through Log Files in Splunk Enterprise

Risk 70
Severity
7.5
First published (updated )

Splunk Splunk Cloud PlatformDenial of Service through coldToFrozen.sh Script in Splunk Enterprise

Risk 40
Severity
7.1
First published (updated )

Splunk MCP Server appSensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app

Risk 66
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Splunk Splunk Cloud PlatformImproper Access Control in Data Model Acceleration in Splunk Enterprise

Risk 22
Severity
4.3
First published (updated )

Splunk Splunk Cloud PlatformImproper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise

Risk 65
Severity
7.1
First published (updated )

Splunk Splunk Cloud PlatformImproper Input Validation during User Account Creation in Splunk Enterprise

Risk 61
Severity
6.6
First published (updated )

Splunk Splunk Cloud PlatformRemote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk Enterprise

Risk 69
Severity
8
First published (updated )

Splunk Splunk Cloud PlatformStored Cross-Site Scripting (XSS) through Path Traversal in Splunk Enterprise

Risk 43
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203