Technology · Splunk
Splunk Enterprise vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 11 vulnerabilities in Splunk Enterprise: 0 in the last 7 days and 3 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-20298, was published on 15 July 2026.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 1
- Exploited in the wild
- 1
About Splunk Enterprise
A platform for searching, monitoring, and analyzing machine-generated big data via a web-style interface.
Latest Splunk Enterprise vulnerabilities
- CVE-2026-20298: Splunk Enterprise and Cloud Platform information disclosure in REST APImediumCVSS 5.3
- CVE-2026-20297: Splunk Enterprise path traversal in App Install REST endpointhighCVSS 7.2
- CVE-2026-20296: Splunk Enterprise CSRF and SPL injection in Deployment ServerhighCVSS 8.3
- CVE-2026-20259: Splunk Enterprise improper access control in saved search ownershipmediumCVSS 5.5
- CVE-2026-20258: Splunk Enterprise stored XSS in classic dashboard HTML panelhighCVSS 7.1
- CVE-2026-20257: Splunk Enterprise and Cloud Platform Data Exfiltration in Classic DashboardsmediumCVSS 5.7
- CVE-2026-20256: Splunk Enterprise and Cloud Platform data exfiltration in Classic DashboardsmediumCVSS 5.7
- CVE-2026-20255: Splunk Enterprise and Cloud Platform data exfiltration in Classic DashboardsmediumCVSS 5.7
- CVE-2026-20254: Splunk Enterprise CSS injection in classic dashboardsmediumCVSS 5.7
- CVE-2026-20253: Splunk Enterprise auth bypass in PostgreSQL sidecar servicecriticalexploited in the wildCVSS 9.8EPSS 1.7%
- CVE-2026-20252: Splunk Enterprise SSRF in Dashboard Studio PDF exporthighCVSS 7.6
Most severe Splunk Enterprise vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-20253: Splunk Enterprise auth bypass in PostgreSQL sidecar servicecriticalexploited in the wildCVSS 9.8EPSS 1.7%
- CVE-2026-20296: Splunk Enterprise CSRF and SPL injection in Deployment ServerhighCVSS 8.3
- CVE-2026-20252: Splunk Enterprise SSRF in Dashboard Studio PDF exporthighCVSS 7.6
- CVE-2026-20297: Splunk Enterprise path traversal in App Install REST endpointhighCVSS 7.2
- CVE-2026-20258: Splunk Enterprise stored XSS in classic dashboard HTML panelhighCVSS 7.1
- CVE-2026-20257: Splunk Enterprise and Cloud Platform Data Exfiltration in Classic DashboardsmediumCVSS 5.7
- CVE-2026-20256: Splunk Enterprise and Cloud Platform data exfiltration in Classic DashboardsmediumCVSS 5.7
- CVE-2026-20255: Splunk Enterprise and Cloud Platform data exfiltration in Classic DashboardsmediumCVSS 5.7
- CVE-2026-20254: Splunk Enterprise CSS injection in classic dashboardsmediumCVSS 5.7
- CVE-2026-20259: Splunk Enterprise improper access control in saved search ownershipmediumCVSS 5.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 3 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/splunk-enterprise.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Splunk Enterprise vulnerabilities", https://junglewise.ai/threats/technologies/splunk-enterprise, 26 September 2026.