Splunk security advisory (AV26-708)
Serial number: AV26-708 Date: July 16, 2026 On July 15, 2026, Splunk published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Splunk Enterprise – multiple versions and platforms Splunk Cloud Platform – multiple versions and platforms The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise Third-Party Package Updates in Splunk Enterprise - July 2026 Splunk Security Advisories
CSIRTS triage
- What
- There are vulnerabilities related to CSRF and path traversal in Splunk Enterprise.
- Who is affected
- Users and administrators of Splunk Enterprise across multiple versions and platforms are affected.
- Urgency
- Remediation is critical due to the severity of the vulnerabilities.
- Action
- Users should apply the necessary updates as recommended in the security advisory.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Splunk Enterprise
Get an email when a new Splunk Enterprise advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/splunk-security-advisory-av26-708
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30