Known vulnerabilities in Splunk Enterprise - page 3

Software CPE: cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*
Total vulnerabilities: 532
Public exploits: 25
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Splunk Enterprise Splunk Enterprise is affected by 532 known vulnerabilities: 31 high, 315 medium, 186 low Critical High Medium Low

Vulnerabilities (532)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144486 - Missing Authentication for Critical Function
CVE-2026-76355
CWE-306 Medium
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144445 - Improper Access Control
CVE-2026-76312
CWE-284 Medium
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144446 - Improper Access Control
CVE-2026-76313
CWE-284 Medium
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144447 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-76314
CWE-94 Medium
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144448 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-76315
CWE-94 Medium
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144449 - Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-76316
CWE-943 High
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144450 - Path Traversal: \'/dir/../filename\'
CVE-2026-76317
CWE-26 Medium
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144451 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-76318
CWE-79 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144452 - Missing Authorization
CVE-2026-76319
CWE-862 Medium
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144453 - Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-76320
CWE-943 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144454 - Command injection
CVE-2026-76321
CWE-77 Medium
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144455 - Missing Authorization
CVE-2026-76322
CWE-862 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144436 - Use of Hard-coded Cryptographic Key
CVE-2026-76258
CWE-321 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144437 - Improper Privilege Management
CVE-2026-76259
CWE-269 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144438 - Incorrect Permission Assignment for Critical Resource
CVE-2026-76260
CWE-732 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144439 - Incorrect Permission Assignment for Critical Resource
CVE-2026-76261
CWE-732 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144441 - Authorization Bypass Through User-Controlled Key
CVE-2026-76263
CWE-639 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144442 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-76309
CWE-89 Low
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144443 - Improper Access Control
CVE-2026-76310
CWE-284 High
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083
#VU144444 - Improper Access Control
CVE-2026-76311
CWE-284 High
No
No
9.4.14, 10.0.9, 10.2.6, 10.4.2 20.08.2026 SB2026082083


Showing elements 41 - 60 out of 532