CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0322 [1.00] [M/H] Vulnerabilities fixed in Splunk Enterprise by Splunk

unknownCVE-2026-76251CVE-2026-76252CVE-2026-76253CVE-2026-76254CVE-2026-76255CVE-2026-76256
Splunk has fixed multiple vulnerabilities in Splunk Enterprise, specifically in versions prior to 10.4.2, 10.2.6, 10.0.9 and 9.4.14. The vulnerabilities in Splunk Enterprise include: - Insufficient enforcement of authentication and authorization controls in REST APIs, allowing unauthorized users to gain access to sensitive data, configurations and leading to execution of arbitrary SPL commands with elevated privileges. - Multiple vulnerabilities that enable Cross-Site Scripting (XSS), where attackers can inject and execute JavaScript through specially crafted links or content in the context of other users. - Furthermore, unauthenticated or low-privileged users can execute commands, manipulate files, or modify configurations via various components such as Dataset Explorer, Dashboard Studio, Search Head Cluster, and other interfaces. - Some vulnerabilities make it possible to access session data, intercept authentication tokens, or force administrative sessions. Exploitation can occur via phishing, opening malicious links, or abuse of insufficiently secured API endpoints. The vulnerabilities affect various components such as the REST API, Splunk Web Manager, Dashboard Studio, federated search, and the Edge Processor component. The impact includes unauthorized access to data, manipulation of system configurations, execution of code with elevated privileges, and potential disruption of service availability. In addition to the mentioned vulnerabilities, Splunk has also released updates to fix vulnerabilities in third-party products used by Splunk. Updates for these vulnerabilities have been released previously and Splunk has now incorporated them into its own software stack.

CSIRTS triage

What
Multiple vulnerabilities in Splunk Enterprise include insufficient authentication and authorization controls allowing unauthorized access, privilege escalation via REST APIs, cross-site scripting, and arbitrary command execution.
Who is affected
Splunk Enterprise deployments running versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected.
Urgency
High urgency; authentication bypass and privilege escalation vulnerabilities enable unauthorized access to sensitive data and arbitrary command execution with elevated privileges.
Action
Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later to resolve CVE-2026-76251 through CVE-2026-76258.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Splunk Enterprise

Get an email when a new Splunk Enterprise advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-21
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0322

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-76251coverage & exploitation statusNVD · CVE.org
CVE-2026-76252coverage & exploitation statusNVD · CVE.org
CVE-2026-76253coverage & exploitation statusNVD · CVE.org
CVE-2026-76254coverage & exploitation statusNVD · CVE.org
CVE-2026-76255coverage & exploitation statusNVD · CVE.org
CVE-2026-76256coverage & exploitation statusNVD · CVE.org
CVE-2026-76257coverage & exploitation statusNVD · CVE.org
CVE-2026-76258coverage & exploitation statusNVD · CVE.org
CVE-2026-76259coverage & exploitation statusNVD · CVE.org
CVE-2026-76260coverage & exploitation statusNVD · CVE.org
CVE-2026-76261coverage & exploitation statusNVD · CVE.org
CVE-2026-76262coverage & exploitation statusNVD · CVE.org
CVE-2026-76263coverage & exploitation statusNVD · CVE.org
CVE-2026-76309coverage & exploitation statusNVD · CVE.org
CVE-2026-76310coverage & exploitation statusNVD · CVE.org
CVE-2026-76311coverage & exploitation statusNVD · CVE.org
CVE-2026-76312coverage & exploitation statusNVD · CVE.org
CVE-2026-76313coverage & exploitation statusNVD · CVE.org
CVE-2026-76314coverage & exploitation statusNVD · CVE.org
CVE-2026-76315coverage & exploitation statusNVD · CVE.org
CVE-2026-76316coverage & exploitation statusNVD · CVE.org
CVE-2026-76317coverage & exploitation statusNVD · CVE.org
CVE-2026-76318coverage & exploitation statusNVD · CVE.org
CVE-2026-76319coverage & exploitation statusNVD · CVE.org
CVE-2026-76320coverage & exploitation statusNVD · CVE.org
CVE-2026-76321coverage & exploitation statusNVD · CVE.org
CVE-2026-76322coverage & exploitation statusNVD · CVE.org
CVE-2026-76323coverage & exploitation statusNVD · CVE.org
CVE-2026-76324coverage & exploitation statusNVD · CVE.org
CVE-2026-76325coverage & exploitation statusNVD · CVE.org
CVE-2026-76326coverage & exploitation statusNVD · CVE.org
CVE-2026-76327coverage & exploitation statusNVD · CVE.org
CVE-2026-76328coverage & exploitation statusNVD · CVE.org
CVE-2026-76329coverage & exploitation statusNVD · CVE.org
CVE-2026-76330coverage & exploitation statusNVD · CVE.org
CVE-2026-76331coverage & exploitation statusNVD · CVE.org
CVE-2026-76332coverage & exploitation statusNVD · CVE.org
CVE-2026-76333coverage & exploitation statusNVD · CVE.org
CVE-2026-76334coverage & exploitation statusNVD · CVE.org
CVE-2026-76335coverage & exploitation statusNVD · CVE.org
CVE-2026-76336coverage & exploitation statusNVD · CVE.org
CVE-2026-76337coverage & exploitation statusNVD · CVE.org
CVE-2026-76338coverage & exploitation statusNVD · CVE.org
CVE-2026-76339coverage & exploitation statusNVD · CVE.org
CVE-2026-76340coverage & exploitation statusNVD · CVE.org
CVE-2026-76341coverage & exploitation statusNVD · CVE.org
CVE-2026-76342coverage & exploitation statusNVD · CVE.org
CVE-2026-76343coverage & exploitation statusNVD · CVE.org

+12 more CVEs referenced in this advisory.

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories