CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Splunk security advisory (AV26-708)

critical
Serial number: AV26-708 Date: July 16, 2026 On July 15, 2026, Splunk published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Splunk Enterprise – multiple versions and platforms Splunk Cloud Platform – multiple versions and platforms The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise Third-Party Package Updates in Splunk Enterprise - July 2026 Splunk Security Advisories

CSIRTS triage

What
There are vulnerabilities related to CSRF and path traversal in Splunk Enterprise.
Who is affected
Users and administrators of Splunk Enterprise across multiple versions and platforms are affected.
Urgency
Remediation is critical due to the severity of the vulnerabilities.
Action
Users should apply the necessary updates as recommended in the security advisory.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Splunk Enterprise

Get an email when a new Splunk Enterprise advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-07-16
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/splunk-security-advisory-av26-708

More from Canadian Centre for Cyber Security