<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Splunk</title>
  <link>https://cvedaily.com/pages/tags/splunk.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/splunk.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Splunk</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-20240 – In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20240</guid>
    <pubDate>Wed, 20 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20240</strong></p>
  <p>In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by exploiting the `coldToFrozen.sh` script in the `splunk_archiver` app to rename critical…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20239 – In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20239</guid>
    <pubDate>Wed, 20 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20239</strong></p>
  <p>In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20238 – In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20238</guid>
    <pubDate>Wed, 20 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20238</strong></p>
  <p>In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7589 – A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7589</guid>
    <pubDate>Fri, 01 May 2026 19:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7589</strong></p>
  <p>A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Impacted is the function create_csv_export of the file services/csv-export-service/app/api/v1/endpoints/csv_export.py of the component CSV Export. This manipulation of the argument job_name causes path traversal. The attack can be initiated remotely. The exploit has been publicly d…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20205 – In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20205</guid>
    <pubDate>Wed, 15 Apr 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20205</strong></p>
  <p>In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.<br><br>The vulnerability would require either local access to the log files or administrative access to internal indexes, which by default only the admin role…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20204 – In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20204</guid>
    <pubDate>Wed, 15 Apr 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20204</strong></p>
  <p>In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform a Remote Code Execution (RCE) by uploading a malicious file to the `$SPLUNK_HOME/var/run/splunk/ap…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20203 – In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20203</guid>
    <pubDate>Wed, 15 Apr 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20203</strong></p>
  <p>In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission on the app, and does not hold the high-privilege capability `accelerate_datamodel`, could turn on or…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20202 – In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20202</guid>
    <pubDate>Wed, 15 Apr 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20202</strong></p>
  <p>In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a specially crafted username that includes a null byte or a non-UTF-8 percent-encoded byte due to improper i…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-176</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20166 – In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20166</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20166</strong></p>
  <p>In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve the Observability Cloud API access token through the Discover Splunk Observability Cloud app due to improper access control.   This vulnerability does not affect Splu…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20165 – In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20165</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20165</strong></p>
  <p>In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, and 9.3.2411.124, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve sensitive information by inspecting the job's search log due to improper access control in the MongoClient logging channel.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20164 – In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20164</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20164</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.11, and 9.3.2411.123, a low-privileged user that does not hold the "admin" or "power" Splunk roles could access the `/splunkd/__raw/servicesNS/-/-/configs/conf-passwords` REST API endpoint, which exposes the hashed or plaintext password values that a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20163 – In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20163</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20163</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that contains the high-privilege capability `edit_cmd` could execute arbitrary shell commands using the `unarchive_cmd` parameter for the `/splunkd/__upload/indexing/preview` REST endpoint.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20162 – In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20162</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20162</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10.2.2510.4, 10.1.2507.15, 10.0.2503.11, and 9.3.2411.123, a low-privileged user who does not hold the "admin" or "power" Splunk roles could craft a malicious payload when creating a View (Settings -  User Interface - Views) at the `/manager/launcher/data/ui/views/_new` endpoint leading…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20144 – In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20144</guid>
    <pubDate>Wed, 18 Feb 2026 18:24:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20144</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the the Splunk _internal index could view the Security Assertion Markup Language (SAML) configurations for Attribute query requests (A…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20142 – In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20142</guid>
    <pubDate>Wed, 18 Feb 2026 18:24:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20142</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the RSA `accessKey` value from the [<u>Authentication.conf</u> ](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/configuration-file-reference/10.2.0-configuration-file…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20141 – In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20141</guid>
    <pubDate>Wed, 18 Feb 2026 18:24:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20141</strong></p>
  <p>In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access the Splunk Monitoring Console App endpoints due to an improper access control. This could lead to a sensitive information disclosure.<br><br>The Monitoring Console app is a bundled app that comes with Splunk Enterprise. It is not available for download…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20139 – In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20139</guid>
    <pubDate>Wed, 18 Feb 2026 18:24:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20139</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload into the `realname`, `tz`, or `email` parameters of the `/splunkd/__raw/services/authentication/users/username` RE…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20138 – In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20138</guid>
    <pubDate>Wed, 18 Feb 2026 18:24:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20138</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the  `integrationKey`, `secretKey`, and `appSecretKey` secrets, generated by [Duo Two-Factor Authentication for Splunk Enterprise](https://duo.com/docs/splunk), in plain text.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-20137 – In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20137</guid>
    <pubDate>Wed, 18 Feb 2026 18:24:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-20137</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the "admin" or "power" Splunk roles could bypass the SPL safeguards for risky commands when they create a Data Model that contains an injected SPL query within an object. They can byp…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20389 – In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20389</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20389</strong></p>
  <p>In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the `label` column field after adding a new device in the Splunk Secure Gateway app. This could potentially…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-20388 – In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20388</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-20388</strong></p>
  <p>In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.7, and 9.3.2411.116, a user who holds a role that contains the high privilege capability `change_authentication` could enumerate internal IP addresses and network ports when adding new search peers to a Splunk search head in a distributed environment.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20387 – In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20387</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20387</strong></p>
  <p>In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20386 – In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20386</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20386</strong></p>
  <p>In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-20385 – In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20385</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-20385</strong></p>
  <p>In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117, a user who holds a role with a high privilege capability `admin_all_objects` could craft a malicious payload through the href attribute of an anchor tag within a collection in the navigation bar, which could result in execution of unauthorized…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20384 – In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20384</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20384</strong></p>
  <p>In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files due to improper validation at the /en-US/static/ web endpoint. This may allow them to poison, forge, or obfuscate sensiti…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20383 – In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20383</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20383</strong></p>
  <p>In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-20382 – In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20382</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-20382</strong></p>
  <p>In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a views dashboard with a custom background using the `data:image/png;base64` protocol that could potentially lead to an unvalidated redirect. This behavi…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20381 – In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_sp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20381</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20381</strong></p>
  <p>In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command allowlist controls in MCP by embedding SPL commands as sub-searches, leading to unauthorized actions beyond the intended MCP restrictions.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-20373 – In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20373</guid>
    <pubDate>Wed, 26 Nov 2025 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-20373</strong></p>
  <p>In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new “Data Security Accounts“. The vulnerability would require either local access to the log files or administrative access to internal indexes, which by default only the admin role receives. Review roles and capabilities on your instance and…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12978 – Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12978</guid>
    <pubDate>Mon, 24 Nov 2025 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12978</strong></p>
  <p>Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote attacker with authenticated or exposed access to these input endpoints can exploit this behavior to manipulate tags and redirect records to un…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12977 – Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to saniti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12977</guid>
    <pubDate>Mon, 24 Nov 2025 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12977</strong></p>
  <p>Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this ca…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-20379 – In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20379</guid>
    <pubDate>Wed, 12 Nov 2025 18:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-20379</strong></p>
  <p>In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-20378 – In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Clou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20378</guid>
    <pubDate>Wed, 12 Nov 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-20378</strong></p>
  <p>In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121, an unauthenticated attacker could craft a malicious URL using the `return_to` parameter of the Splunk Web login endpoint. When an authenticated user visits the malicious URL, it could cause an unvalidated redirect to an external malicious site. To…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20371 – In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20371</guid>
    <pubDate>Wed, 01 Oct 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20371</strong></p>
  <p>In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an authenticated high-privileged user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20370 – In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20370</guid>
    <pubDate>Wed, 01 Oct 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20370</strong></p>
  <p>In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the high-privilege capability `change_authentication`, could send multiple LDAP bind requests to a specific internal endpoint, resulting in high server CPU usage, which could potentially lead to a denial of…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20369 – In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20369</guid>
    <pubDate>Wed, 01 Oct 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20369</strong></p>
  <p>In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-776</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20368 – In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20368</guid>
    <pubDate>Wed, 01 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20368</strong></p>
  <p>In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through the error messages and job inspection details of a saved search. This could result in execution of unauthorized JavaScript code in the brow…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20367 – In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20367</guid>
    <pubDate>Wed, 01 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20367</strong></p>
  <p>In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious payload through the `dataset.command` parameter of the `/app/search/table` endpoint, which could result in execution of unauthorized JavaScript code in…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20366 – In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20366</guid>
    <pubDate>Wed, 01 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20366</strong></p>
  <p>In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in the background. If the low privileged user guesses the search job’s unique Search…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-20325 – In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20325</guid>
    <pubDate>Mon, 07 Jul 2025 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-20325</strong></p>
  <p>In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.113, and 9.2.2406.119, the software potentially exposes the search head cluster [splunk.secret](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.4/install-splunk-enterprise-securely/deploy-secure-passwords-across-multiple-servers)…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20324 – In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20324</guid>
    <pubDate>Mon, 07 Jul 2025 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20324</strong></p>
  <p>In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create or overwrite [system source type](https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.2/configure-source-types/create-source-types) con…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20323 – In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20323</guid>
    <pubDate>Mon, 07 Jul 2025 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20323</strong></p>
  <p>In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search `Bucket Copy Trigger` within the Splunk Archiver application. This is because of missing access controls in the saved searches for this app.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20322 – In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20322</guid>
    <pubDate>Mon, 07 Jul 2025 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20322</strong></p>
  <p>In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, an unauthenticated attacker could send a specially-crafted SPL search command that could trigger a rolling restart in the Search Head Cluster through a Cross-Site Request Forgery (CSRF), potentially leading to a denial of service (DoS).<br><br…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20321 – In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20321</guid>
    <pubDate>Mon, 07 Jul 2025 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20321</strong></p>
  <p>In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.114, and 9.2.2406.119, an unauthenticated attacker can send a specially-crafted SPL search that could change the membership state in a Splunk Search Head Cluster (SHC) through a Cross-Site Request Forgery (CSRF), potentially leading to the removal of the captain or a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20320 – In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20320</guid>
    <pubDate>Mon, 07 Jul 2025 18:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20320</strong></p>
  <p>In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.107, 9.3.2408.117, and 9.2.2406.121, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the `User Interface - Views` configuration page that could potentially lead to a denial of service (DoS).The user could cause t…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20319 – In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20319</guid>
    <pubDate>Mon, 07 Jul 2025 18:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20319</strong></p>
  <p>In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-privilege capability `edit_scripted` and `list_inputs` capability , could perform a remote command execution due to improper user input sanitization on the scripted input files.<br><br>See [Define roles on the Splunk platform with capabilities](https://docs.splunk.com/Documentation/…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20300 – In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20300</guid>
    <pubDate>Mon, 07 Jul 2025 18:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20300</strong></p>
  <p>In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.112, and 9.2.2406.119, a low-privileged user that does not hold the "admin" or "power" Splunk roles, and has read-only access to a specific alert, could suppress that alert when it triggers. See [Define alert suppression groups to throttle sets of similar alerts](http…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20297 – In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20297</guid>
    <pubDate>Mon, 02 Jun 2025 18:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20297</strong></p>
  <p>In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the pdfgen/render REST endpoint that could result in execution of unauthorized JavaScript code in the browser of a user.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20230 – In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20230</guid>
    <pubDate>Wed, 26 Mar 2025 23:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20230</strong></p>
  <p>In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could edit and delete other user data in App Key Value Store (KVStore) collections that the Splunk Secure Gateway app created. This is due to missing access c…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-20233 – In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20233</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-20233</strong></p>
  <p>In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20232 – In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20232</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20232</strong></p>
  <p>In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.2312.208 and 9.1.2308.212, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on t…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20231 – In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20231</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20231</strong></p>
  <p>In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a search using the permissions of a higher-privileged user that could lead to disclosure of sensitive information.<br><br>The vulnerability requires…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20229 – In Splunk Enterprise versions below 9.3.3, 9.2.5,  and 9.1.8, and Splunk Cloud P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20229</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20229</strong></p>
  <p>In Splunk Enterprise versions below 9.3.3, 9.2.5,  and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) through a file upload to the "$SPLUNK_HOME/var/run/splunk/apptemp" directory due to missing authorization checks.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20228 – In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20228</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20228</strong></p>
  <p>In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20227 – In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20227</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20227</strong></p>
  <p>In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.112, 9.2.2403.115, 9.1.2312.208 and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could bypass the external content warning modal dialog box in Dashboard Studio dashboards which could lead to an information disclosure.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20226 – In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20226</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20226</strong></p>
  <p>In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.111, and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on the "/services/stream…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0367 – In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0367</guid>
    <pubDate>Thu, 30 Jan 2025 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0367</strong></p>
  <p>In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22621 – In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22621</guid>
    <pubDate>Tue, 07 Jan 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22621</strong></p>
  <p>In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin"  Splunk roles.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53247 – In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53247</guid>
    <pubDate>Tue, 10 Dec 2024 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53247</strong></p>
  <p>In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could perform a Remote Code Execution (RCE).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-53246 – In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53246</guid>
    <pubDate>Tue, 10 Dec 2024 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-53246</strong></p>
  <p>In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially disclose sensitive information. The vulnerability requires the exploitation of another vulnerability, such as a Risky Commands Bypass, for successful exploitation.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-53245 – In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53245</guid>
    <pubDate>Tue, 10 Dec 2024 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-53245</strong></p>
  <p>In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles, that has a username with the same name as a role with read access to dashboards, could see the dashboard name and the dashboard XML by cloning the dashboard.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-53244 – In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53244</guid>
    <pubDate>Tue, 10 Dec 2024 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-53244</strong></p>
  <p>In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on “/en-US/app/search/report“ e…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-53243 – In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53243</guid>
    <pubDate>Tue, 10 Dec 2024 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-53243</strong></p>
  <p>In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could see alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints due to improper access control.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45741 – In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45741</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45741</strong></p>
  <p>In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom configuration file that the "api.uri" parameter from the "/manager/search/apps/local" endpoint in Splunk Web calls. This could result in execution o…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45740 – In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45740</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45740</strong></p>
  <p>In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through Scheduled Views that could result in execution of unauthorized JavaScript code in the browser of a user.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45739 – In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45739</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45739</strong></p>
  <p>In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log channel at the DEBUG logging level.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45738 – In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45738</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45738</strong></p>
  <p>In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG logging level.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45737 – In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45737</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45737</strong></p>
  <p>In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45736 – In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Pla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45736</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45736</strong></p>
  <p>In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with an improperly formatted  "INGEST_EVAL" parameter as part of a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowle…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45735 – In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45735</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45735</strong></p>
  <p>In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold the "admin" or "power" Splunk roles can see App Key Value Store (KV Store) deployment configuration and public/private keys in the Splunk Secure Gateway App.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45734 – In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45734</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45734</strong></p>
  <p>In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboards. The images on the  machine could be exposed by exporting the dashboard as a PDF, using the local image path in the img tag in the source extensi…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45733 – In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45733</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45733</strong></p>
  <p>In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45732 – In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45732</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45732</strong></p>
  <p>In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the "nobody" Splunk user in the SplunkDeploymentServerConfig app. This could let the low-privileged user access potentially r…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45731 – In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45731</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45731</strong></p>
  <p>In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk Enterprise for Windows is installed on a separate drive.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36997 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36997</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36997</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could potentially cause a persistent cross-site scripting (XSS) exploit.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36996 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36996</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36996</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they would likely receive from the instance when they attempt to log in. This disclosure could then lead to additional brute-force password-guessing attacks. This vu…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36995 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36995</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36995</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could create experimental items.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36994 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36994</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36994</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View and Splunk Web Bulletin Messages that could result in execution of unauthorized JavaScript code in the browser of a user.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36993 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36993</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36993</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a Splunk Web Bulletin Messages that could result in execution of unauthorized JavaScript code in the browser of a user.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36992 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36992</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36992</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View that could result in execution of unauthorized JavaScript code in the browser of a user. The “url” parameter of the Dashboard element does not hav…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36991 – In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36991</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36991</strong></p>
  <p>In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36990 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36990</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36990</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the admin or power Splunk roles could send a specially crafted HTTP POST request to the datamodel/web REST endpoint in Splunk Enterprise, potentially causing a denial of service.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36989 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36989</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36989</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36987 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36987</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36987</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the admin or power Splunk roles could upload a file with an arbitrary extension using the indexing/preview REST endpoint.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36986 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36986</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36986</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user to phish the victim by tricking them into initi…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36985 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36985</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36985</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-687</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36984 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36984</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36984</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36983 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36983</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36983</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36982 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36982</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36982</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35291 – Cross-site scripting vulnerability exists in Splunk Config Explorer versions pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35291</guid>
    <pubDate>Mon, 27 May 2024 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35291</strong></p>
  <p>Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-29946 – In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29946</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-29946</strong></p>
  <p>In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-29945 – In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29945</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-29945</strong></p>
  <p>In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. This exposure happens when either Splunk Enterprise runs in debug mode or the JsonWebToken component has been configured to log its activity at the DEBUG logging level.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46231 – In Splunk Add-on Builder versions below 4.1.4, the application writes user sessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46231</guid>
    <pubDate>Tue, 30 Jan 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46231</strong></p>
  <p>In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46230 – In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive informat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46230</guid>
    <pubDate>Tue, 30 Jan 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46230</strong></p>
  <p>In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23678 – In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23678</guid>
    <pubDate>Mon, 22 Jan 2024 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23678</strong></p>
  <p>In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23677 – In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility disclose...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23677</guid>
    <pubDate>Mon, 22 Jan 2024 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23677</strong></p>
  <p>In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23676 – In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23676</guid>
    <pubDate>Mon, 22 Jan 2024 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23676</strong></p>
  <p>In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have permission to view. This vulnerability requires user interaction from a high-privileged user to exploit.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23675 – In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23675</guid>
    <pubDate>Mon, 22 Jan 2024 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23675</strong></p>
  <p>In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22165 – In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22165</guid>
    <pubDate>Tue, 09 Jan 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22165</strong></p>
  <p>In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations manager until it is deleted.<br>The vulnerability requires an authenticated session and access to create an Investigation. It only affects the availability of the…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22164 – In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use inv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22164</guid>
    <pubDate>Tue, 09 Jan 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22164</strong></p>
  <p>In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22164">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
