{"schema_version":1,"title":"Splunk Enterprise vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in Splunk Enterprise: 0 in the last 7 days and 3 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-20298, was published on 15 July 2026.","url":"https://junglewise.ai/threats/technologies/splunk-enterprise","json_url":"https://junglewise.ai/threats/technologies/splunk-enterprise.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/splunk-enterprise","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":11,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":3,"last_365_days":11},"latest":[{"cve":"CVE-2026-20298","cvss":5.3,"slug":"cve-2026-20298-splunk-enterprise-and-cloud-platform-information-disclosure-in","title":"Splunk Enterprise and Cloud Platform information disclosure in REST API","severity":"medium","exploited":false,"published_at":"2026-07-15T18:16:44.993+00:00","url":"https://junglewise.ai/threats/cve-2026-20298-splunk-enterprise-and-cloud-platform-information-disclosure-in"},{"cve":"CVE-2026-20297","cvss":7.2,"slug":"cve-2026-20297-splunk-enterprise-path-traversal-in-app-install-rest-endpoint","title":"Splunk Enterprise path traversal in App Install REST endpoint","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:44.88+00:00","url":"https://junglewise.ai/threats/cve-2026-20297-splunk-enterprise-path-traversal-in-app-install-rest-endpoint"},{"cve":"CVE-2026-20296","cvss":8.3,"slug":"cve-2026-20296-splunk-enterprise-csrf-and-spl-injection-in-deployment-server","title":"Splunk Enterprise CSRF and SPL injection in Deployment Server","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:44.74+00:00","url":"https://junglewise.ai/threats/cve-2026-20296-splunk-enterprise-csrf-and-spl-injection-in-deployment-server"},{"cve":"CVE-2026-20259","cvss":5.5,"slug":"cve-2026-20259-splunk-enterprise-improper-access-control-in-saved-search","title":"Splunk Enterprise improper access control in saved search ownership","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:41.503+00:00","url":"https://junglewise.ai/threats/cve-2026-20259-splunk-enterprise-improper-access-control-in-saved-search"},{"cve":"CVE-2026-20258","cvss":7.1,"slug":"cve-2026-20258-splunk-enterprise-stored-xss-in-classic-dashboard-html-panel","title":"Splunk Enterprise stored XSS in classic dashboard HTML panel","severity":"high","exploited":false,"published_at":"2026-06-10T18:16:41.377+00:00","url":"https://junglewise.ai/threats/cve-2026-20258-splunk-enterprise-stored-xss-in-classic-dashboard-html-panel"},{"cve":"CVE-2026-20257","cvss":5.7,"slug":"cve-2026-20257-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic","title":"Splunk Enterprise and Cloud Platform Data Exfiltration in Classic Dashboards","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:41.257+00:00","url":"https://junglewise.ai/threats/cve-2026-20257-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic"},{"cve":"CVE-2026-20256","cvss":5.7,"slug":"cve-2026-20256-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic","title":"Splunk Enterprise and Cloud Platform data exfiltration in Classic Dashboards","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:41.133+00:00","url":"https://junglewise.ai/threats/cve-2026-20256-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic"},{"cve":"CVE-2026-20255","cvss":5.7,"slug":"cve-2026-20255-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic","title":"Splunk Enterprise and Cloud Platform data exfiltration in Classic Dashboards","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:41.01+00:00","url":"https://junglewise.ai/threats/cve-2026-20255-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic"},{"cve":"CVE-2026-20254","cvss":5.7,"slug":"cve-2026-20254-splunk-enterprise-css-injection-in-classic-dashboards","title":"Splunk Enterprise CSS injection in classic dashboards","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:40.887+00:00","url":"https://junglewise.ai/threats/cve-2026-20254-splunk-enterprise-css-injection-in-classic-dashboards"},{"cve":"CVE-2026-20253","cvss":9.8,"epss":0.0173,"slug":"cve-2026-20253-splunk-enterprise-auth-bypass-in-postgresql-sidecar-service","title":"Splunk Enterprise auth bypass in PostgreSQL sidecar service","severity":"critical","exploited":true,"published_at":"2026-06-10T18:16:40.76+00:00","url":"https://junglewise.ai/threats/cve-2026-20253-splunk-enterprise-auth-bypass-in-postgresql-sidecar-service"},{"cve":"CVE-2026-20252","cvss":7.6,"slug":"cve-2026-20252-splunk-enterprise-ssrf-in-dashboard-studio-pdf-export","title":"Splunk Enterprise SSRF in Dashboard Studio PDF export","severity":"high","exploited":false,"published_at":"2026-06-10T18:16:40.63+00:00","url":"https://junglewise.ai/threats/cve-2026-20252-splunk-enterprise-ssrf-in-dashboard-studio-pdf-export"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Splunk SOAR","slug":"soar","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/soar"},{"name":"Splunk Cloud Platform","slug":"cloud-platform","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/cloud-platform"},{"name":"Splunk AI Toolkit","slug":"ai-toolkit","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ai-toolkit"},{"name":"Splunk Connect For Kafka","slug":"connect-for-kafka","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/connect-for-kafka"},{"name":"Splunk Secure Gateway","slug":"secure-gateway","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/secure-gateway"},{"name":"Splunk","slug":"splunk","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/splunk"}],"technology":{"hub":true,"name":"Splunk Enterprise","slug":"splunk-enterprise","vendor":{"name":"Splunk","slug":"splunk","url":"https://junglewise.ai/threats/vendors/splunk"},"aliases":[],"category":"application","homepage":"https://www.splunk.com/en_us/products/splunk-enterprise.html","description":"A platform for searching, monitoring, and analyzing machine-generated big data via a web-style interface.","url":"https://junglewise.ai/threats/technologies/splunk-enterprise"},"most_severe":[{"cve":"CVE-2026-20253","cvss":9.8,"epss":0.0173,"slug":"cve-2026-20253-splunk-enterprise-auth-bypass-in-postgresql-sidecar-service","title":"Splunk Enterprise auth bypass in PostgreSQL sidecar service","severity":"critical","exploited":true,"published_at":"2026-06-10T18:16:40.76+00:00","url":"https://junglewise.ai/threats/cve-2026-20253-splunk-enterprise-auth-bypass-in-postgresql-sidecar-service"},{"cve":"CVE-2026-20296","cvss":8.3,"slug":"cve-2026-20296-splunk-enterprise-csrf-and-spl-injection-in-deployment-server","title":"Splunk Enterprise CSRF and SPL injection in Deployment Server","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:44.74+00:00","url":"https://junglewise.ai/threats/cve-2026-20296-splunk-enterprise-csrf-and-spl-injection-in-deployment-server"},{"cve":"CVE-2026-20252","cvss":7.6,"slug":"cve-2026-20252-splunk-enterprise-ssrf-in-dashboard-studio-pdf-export","title":"Splunk Enterprise SSRF in Dashboard Studio PDF export","severity":"high","exploited":false,"published_at":"2026-06-10T18:16:40.63+00:00","url":"https://junglewise.ai/threats/cve-2026-20252-splunk-enterprise-ssrf-in-dashboard-studio-pdf-export"},{"cve":"CVE-2026-20297","cvss":7.2,"slug":"cve-2026-20297-splunk-enterprise-path-traversal-in-app-install-rest-endpoint","title":"Splunk Enterprise path traversal in App Install REST endpoint","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:44.88+00:00","url":"https://junglewise.ai/threats/cve-2026-20297-splunk-enterprise-path-traversal-in-app-install-rest-endpoint"},{"cve":"CVE-2026-20258","cvss":7.1,"slug":"cve-2026-20258-splunk-enterprise-stored-xss-in-classic-dashboard-html-panel","title":"Splunk Enterprise stored XSS in classic dashboard HTML panel","severity":"high","exploited":false,"published_at":"2026-06-10T18:16:41.377+00:00","url":"https://junglewise.ai/threats/cve-2026-20258-splunk-enterprise-stored-xss-in-classic-dashboard-html-panel"},{"cve":"CVE-2026-20257","cvss":5.7,"slug":"cve-2026-20257-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic","title":"Splunk Enterprise and Cloud Platform Data Exfiltration in Classic Dashboards","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:41.257+00:00","url":"https://junglewise.ai/threats/cve-2026-20257-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic"},{"cve":"CVE-2026-20256","cvss":5.7,"slug":"cve-2026-20256-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic","title":"Splunk Enterprise and Cloud Platform data exfiltration in Classic Dashboards","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:41.133+00:00","url":"https://junglewise.ai/threats/cve-2026-20256-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic"},{"cve":"CVE-2026-20255","cvss":5.7,"slug":"cve-2026-20255-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic","title":"Splunk Enterprise and Cloud Platform data exfiltration in Classic Dashboards","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:41.01+00:00","url":"https://junglewise.ai/threats/cve-2026-20255-splunk-enterprise-and-cloud-platform-data-exfiltration-in-classic"},{"cve":"CVE-2026-20254","cvss":5.7,"slug":"cve-2026-20254-splunk-enterprise-css-injection-in-classic-dashboards","title":"Splunk Enterprise CSS injection in classic dashboards","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:40.887+00:00","url":"https://junglewise.ai/threats/cve-2026-20254-splunk-enterprise-css-injection-in-classic-dashboards"},{"cve":"CVE-2026-20259","cvss":5.5,"slug":"cve-2026-20259-splunk-enterprise-improper-access-control-in-saved-search","title":"Splunk Enterprise improper access control in saved search ownership","severity":"medium","exploited":false,"published_at":"2026-06-10T18:16:41.503+00:00","url":"https://junglewise.ai/threats/cve-2026-20259-splunk-enterprise-improper-access-control-in-saved-search"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}