{"schema_version":1,"title":"Splunk vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 68 vulnerabilities in Splunk: 0 in the last 7 days and 53 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-76405, was published on 19 August 2026. 7 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/splunk","json_url":"https://junglewise.ai/threats/vendors/splunk.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/splunk","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":21,"all_time":68,"critical":3,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":53,"last_365_days":68},"latest":[{"cve":"CVE-2026-76405","cvss":4.3,"epss":0.0019,"slug":"cve-2026-76405-splunk-on-call-information-disclosure-in-app-key-value-store","title":"Splunk On-Call information disclosure in App Key Value Store","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:27.297+00:00","url":"https://junglewise.ai/threats/cve-2026-76405-splunk-on-call-information-disclosure-in-app-key-value-store"},{"cve":"CVE-2026-76404","cvss":9.1,"epss":0.0075,"slug":"cve-2026-76404-splunk-mcp-server-app-remote-code-execution-through","title":"Splunk MCP Server app remote code execution through deserialization","severity":"critical","exploited":false,"published_at":"2026-08-19T22:17:27.17+00:00","url":"https://junglewise.ai/threats/cve-2026-76404-splunk-mcp-server-app-remote-code-execution-through"},{"cve":"CVE-2026-76403","cvss":7.4,"epss":0.0024,"slug":"cve-2026-76403-splunk-connect-for-kafka-improper-certificate-validation-in","title":"Splunk Connect for Kafka improper certificate validation in Kerberos authentication","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:27.043+00:00","url":"https://junglewise.ai/threats/cve-2026-76403-splunk-connect-for-kafka-improper-certificate-validation-in"},{"cve":"CVE-2026-76402","cvss":8.2,"epss":0.0041,"slug":"cve-2026-76402-splunk-connect-for-kafka-server-side-request-forgery-via-rest-api","title":"Splunk Connect for Kafka server-side request forgery via REST API","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:26.91+00:00","url":"https://junglewise.ai/threats/cve-2026-76402-splunk-connect-for-kafka-server-side-request-forgery-via-rest-api"},{"cve":"CVE-2026-76401","cvss":5.9,"epss":0.0038,"slug":"cve-2026-76401-splunk-connect-for-kafka-regular-expression-denial-of-service","title":"Splunk Connect for Kafka regular expression denial of service","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:26.78+00:00","url":"https://junglewise.ai/threats/cve-2026-76401-splunk-connect-for-kafka-regular-expression-denial-of-service"},{"cve":"CVE-2026-76400","cvss":5.9,"epss":0.0038,"slug":"cve-2026-76400-splunk-connect-for-kafka-denial-of-service-in-rest-api","title":"Splunk Connect for Kafka denial of service in REST API","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:26.647+00:00","url":"https://junglewise.ai/threats/cve-2026-76400-splunk-connect-for-kafka-denial-of-service-in-rest-api"},{"cve":"CVE-2026-76399","cvss":8.1,"epss":0.0035,"slug":"cve-2026-76399-splunk-ai-toolkit-incorrect-permission-assignment-for-scheduled","title":"Splunk AI Toolkit incorrect permission assignment for scheduled searches","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:26.523+00:00","url":"https://junglewise.ai/threats/cve-2026-76399-splunk-ai-toolkit-incorrect-permission-assignment-for-scheduled"},{"cve":"CVE-2026-76398","cvss":4.3,"epss":0.0025,"slug":"cve-2026-76398-splunk-ai-toolkit-improper-access-control-in-experiment-history","title":"Splunk AI Toolkit improper access control in experiment history deletion","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:26.4+00:00","url":"https://junglewise.ai/threats/cve-2026-76398-splunk-ai-toolkit-improper-access-control-in-experiment-history"},{"cve":"CVE-2026-76397","cvss":8.1,"epss":0.0035,"slug":"cve-2026-76397-splunk-ai-toolkit-improper-access-control-in-experiment-history","title":"Splunk AI Toolkit improper access control in experiment history","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:26.27+00:00","url":"https://junglewise.ai/threats/cve-2026-76397-splunk-ai-toolkit-improper-access-control-in-experiment-history"},{"cve":"CVE-2026-76396","cvss":7.5,"epss":0.0032,"slug":"cve-2026-76396-splunk-ai-toolkit-improper-access-control-in-scheduled-searches","title":"Splunk AI Toolkit improper access control in scheduled searches","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:26.15+00:00","url":"https://junglewise.ai/threats/cve-2026-76396-splunk-ai-toolkit-improper-access-control-in-scheduled-searches"},{"cve":"CVE-2026-76395","cvss":8.8,"epss":0.0065,"slug":"cve-2026-76395-splunk-ai-toolkit-rce-through-unsafe-model-deserialization","title":"Splunk AI Toolkit RCE through unsafe model deserialization","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:26.023+00:00","url":"https://junglewise.ai/threats/cve-2026-76395-splunk-ai-toolkit-rce-through-unsafe-model-deserialization"},{"cve":"CVE-2026-76394","cvss":8.3,"epss":0.0035,"slug":"cve-2026-76394-splunk-ai-toolkit-missing-authorization-in-rest-api-container","title":"Splunk AI Toolkit missing authorization in REST API container management","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:25.87+00:00","url":"https://junglewise.ai/threats/cve-2026-76394-splunk-ai-toolkit-missing-authorization-in-rest-api-container"},{"cve":"CVE-2026-76393","cvss":5.9,"epss":0.0018,"slug":"cve-2026-76393-splunk-ai-toolkit-race-condition-in-model-upload","title":"Splunk AI Toolkit race condition in model upload","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:25.737+00:00","url":"https://junglewise.ai/threats/cve-2026-76393-splunk-ai-toolkit-race-condition-in-model-upload"},{"cve":"CVE-2026-76392","cvss":5.4,"epss":0.0023,"slug":"cve-2026-76392-splunk-ai-toolkit-hard-coded-credentials-in-container-connections","title":"Splunk AI Toolkit hard-coded credentials in container connections","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:25.613+00:00","url":"https://junglewise.ai/threats/cve-2026-76392-splunk-ai-toolkit-hard-coded-credentials-in-container-connections"},{"cve":"CVE-2026-76391","cvss":8.3,"epss":0.0047,"slug":"cve-2026-76391-splunk-ai-toolkit-privilege-escalation-in-agent-run-history","title":"Splunk AI Toolkit privilege escalation in Agent Run History","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:25.487+00:00","url":"https://junglewise.ai/threats/cve-2026-76391-splunk-ai-toolkit-privilege-escalation-in-agent-run-history"},{"cve":"CVE-2026-76388","cvss":8.1,"epss":0.0035,"slug":"cve-2026-76388-splunk-enterprise-security-privilege-escalation-through-search","title":"Splunk Enterprise Security privilege escalation through search macro permissions","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:25.09+00:00","url":"https://junglewise.ai/threats/cve-2026-76388-splunk-enterprise-security-privilege-escalation-through-search"},{"cve":"CVE-2026-76387","cvss":8.1,"epss":0.004,"slug":"cve-2026-76387-splunk-enterprise-security-spl-injection-in-analyst-queue","title":"Splunk Enterprise Security SPL injection in Analyst Queue","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:24.953+00:00","url":"https://junglewise.ai/threats/cve-2026-76387-splunk-enterprise-security-spl-injection-in-analyst-queue"},{"cve":"CVE-2026-76386","cvss":4.3,"epss":0.0019,"slug":"cve-2026-76386-splunk-zoom-app-for-soar-password-disclosure-in-action-parameters","title":"Splunk Zoom app for SOAR password disclosure in action parameters","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:24.833+00:00","url":"https://junglewise.ai/threats/cve-2026-76386-splunk-zoom-app-for-soar-password-disclosure-in-action-parameters"},{"cve":"CVE-2026-76385","cvss":4.3,"epss":0.0012,"slug":"cve-2026-76385-venafi-app-for-splunk-soar-information-disclosure-in-action","title":"Venafi app for Splunk SOAR information disclosure in action parameters","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:24.71+00:00","url":"https://junglewise.ai/threats/cve-2026-76385-venafi-app-for-splunk-soar-information-disclosure-in-action"},{"cve":"CVE-2026-76384","cvss":4.3,"epss":0.0019,"slug":"cve-2026-76384-splunk-attack-analyzer-connector-information-disclosure-in-action","title":"Splunk Attack Analyzer Connector information disclosure in action parameters","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:24.587+00:00","url":"https://junglewise.ai/threats/cve-2026-76384-splunk-attack-analyzer-connector-information-disclosure-in-action"},{"cve":"CVE-2026-76383","cvss":4.3,"epss":0.0021,"slug":"cve-2026-76383-rsa-securid-authentication-manager-information-disclosure-in","title":"RSA SecurID Authentication Manager information disclosure in action parameters","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:24.467+00:00","url":"https://junglewise.ai/threats/cve-2026-76383-rsa-securid-authentication-manager-information-disclosure-in"},{"cve":"CVE-2026-76382","cvss":4.3,"epss":0.0019,"slug":"cve-2026-76382-splunk-phantom-app-for-soar-information-disclosure-in-action","title":"Splunk Phantom app for SOAR information disclosure in action parameters","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:24.34+00:00","url":"https://junglewise.ai/threats/cve-2026-76382-splunk-phantom-app-for-soar-information-disclosure-in-action"},{"cve":"CVE-2026-76381","cvss":4.3,"epss":0.0019,"slug":"cve-2026-76381-splunk-ms-graph-for-active-directory-app-information-disclosure","title":"Splunk MS Graph for Active Directory app information disclosure through unmasked password parameter","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:24.203+00:00","url":"https://junglewise.ai/threats/cve-2026-76381-splunk-ms-graph-for-active-directory-app-information-disclosure"},{"cve":"CVE-2026-76377","cvss":4.3,"epss":0.0019,"slug":"cve-2026-76377-splunk-azure-ad-graph-app-information-disclosure-in-action","title":"Splunk Azure AD Graph app information disclosure in action parameters","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:23.697+00:00","url":"https://junglewise.ai/threats/cve-2026-76377-splunk-azure-ad-graph-app-information-disclosure-in-action"},{"cve":"CVE-2026-76376","cvss":4.3,"epss":0.0019,"slug":"cve-2026-76376-splunk-aws-iam-app-for-soar-information-disclosure-through-action","title":"Splunk AWS IAM app for SOAR information disclosure through action parameters","severity":"medium","exploited":false,"published_at":"2026-08-19T22:17:23.577+00:00","url":"https://junglewise.ai/threats/cve-2026-76376-splunk-aws-iam-app-for-soar-information-disclosure-through-action"}],"vendor":{"hub":true,"name":"Splunk","slug":"splunk","homepage":"https://www.splunk.com/","description":"Splunk is an American software company that produces software for searching, monitoring, and analyzing machine-generated big data.","url":"https://junglewise.ai/threats/vendors/splunk"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":50},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-20253","cvss":9.8,"epss":0.0173,"slug":"cve-2026-20253-splunk-enterprise-auth-bypass-in-postgresql-sidecar-service","title":"Splunk Enterprise auth bypass in PostgreSQL sidecar service","severity":"critical","exploited":true,"published_at":"2026-06-10T18:16:40.76+00:00","url":"https://junglewise.ai/threats/cve-2026-20253-splunk-enterprise-auth-bypass-in-postgresql-sidecar-service"},{"cve":"CVE-2026-76404","cvss":9.1,"epss":0.0075,"slug":"cve-2026-76404-splunk-mcp-server-app-remote-code-execution-through","title":"Splunk MCP Server app remote code execution through deserialization","severity":"critical","exploited":false,"published_at":"2026-08-19T22:17:27.17+00:00","url":"https://junglewise.ai/threats/cve-2026-76404-splunk-mcp-server-app-remote-code-execution-through"},{"cve":"CVE-2026-20266","cvss":9.1,"epss":0.0045,"slug":"cve-2026-20266-splunk-ai-toolkit-os-command-injection-in-btool-configuration","title":"Splunk AI Toolkit OS command injection in btool configuration helper","severity":"critical","exploited":false,"published_at":"2026-06-17T18:17:40.9+00:00","url":"https://junglewise.ai/threats/cve-2026-20266-splunk-ai-toolkit-os-command-injection-in-btool-configuration"},{"cve":"CVE-2026-76395","cvss":8.8,"epss":0.0065,"slug":"cve-2026-76395-splunk-ai-toolkit-rce-through-unsafe-model-deserialization","title":"Splunk AI Toolkit RCE through unsafe model deserialization","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:26.023+00:00","url":"https://junglewise.ai/threats/cve-2026-76395-splunk-ai-toolkit-rce-through-unsafe-model-deserialization"},{"cve":"CVE-2026-76351","cvss":8.8,"epss":0.0042,"slug":"cve-2026-76351-splunk-enterprise-privilege-escalation-via-report-notification","title":"Splunk Enterprise privilege escalation via report notification data","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:20.07+00:00","url":"https://junglewise.ai/threats/cve-2026-76351-splunk-enterprise-privilege-escalation-via-report-notification"},{"cve":"CVE-2026-20251","cvss":8.8,"slug":"cve-2026-20251-splunk-secure-gateway-unsafe-deserialization-remote-code","title":"Splunk Secure Gateway unsafe deserialization remote code execution","severity":"high","exploited":false,"published_at":"2026-06-10T18:16:40.477+00:00","url":"https://junglewise.ai/threats/cve-2026-20251-splunk-secure-gateway-unsafe-deserialization-remote-code"},{"cve":"CVE-2026-76391","cvss":8.3,"epss":0.0047,"slug":"cve-2026-76391-splunk-ai-toolkit-privilege-escalation-in-agent-run-history","title":"Splunk AI Toolkit privilege escalation in Agent Run History","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:25.487+00:00","url":"https://junglewise.ai/threats/cve-2026-76391-splunk-ai-toolkit-privilege-escalation-in-agent-run-history"},{"cve":"CVE-2026-76394","cvss":8.3,"epss":0.0035,"slug":"cve-2026-76394-splunk-ai-toolkit-missing-authorization-in-rest-api-container","title":"Splunk AI Toolkit missing authorization in REST API container management","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:25.87+00:00","url":"https://junglewise.ai/threats/cve-2026-76394-splunk-ai-toolkit-missing-authorization-in-rest-api-container"},{"cve":"CVE-2026-20296","cvss":8.3,"slug":"cve-2026-20296-splunk-enterprise-csrf-and-spl-injection-in-deployment-server","title":"Splunk Enterprise CSRF and SPL injection in Deployment Server","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:44.74+00:00","url":"https://junglewise.ai/threats/cve-2026-20296-splunk-enterprise-csrf-and-spl-injection-in-deployment-server"},{"cve":"CVE-2026-76402","cvss":8.2,"epss":0.0041,"slug":"cve-2026-76402-splunk-connect-for-kafka-server-side-request-forgery-via-rest-api","title":"Splunk Connect for Kafka server-side request forgery via REST API","severity":"high","exploited":false,"published_at":"2026-08-19T22:17:26.91+00:00","url":"https://junglewise.ai/threats/cve-2026-76402-splunk-connect-for-kafka-server-side-request-forgery-via-rest-api"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Splunk SOAR","slug":"soar","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/soar"},{"name":"Splunk Cloud Platform","slug":"cloud-platform","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/cloud-platform"},{"name":"Splunk AI Toolkit","slug":"ai-toolkit","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ai-toolkit"},{"name":"Splunk Enterprise","slug":"splunk-enterprise","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/splunk-enterprise"},{"name":"Splunk Connect For Kafka","slug":"connect-for-kafka","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/connect-for-kafka"},{"name":"Splunk Secure Gateway","slug":"secure-gateway","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/secure-gateway"},{"name":"Splunk","slug":"splunk","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/splunk"}]}