Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-76278 — Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State Transfer (REST…

splunk | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.1 MEDIUM
CVE-2026-76277 — Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enter…

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vuln…

splunk | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-76276 — Information Disclosure in the Discover Splunk Observability Cloud app through Splunk Web …

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve original source code for the Discover Splu…

splunk | Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-76275 — Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search query text and job metadata for jobs that bel…

splunk | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-76274 — Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observab…

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observabi…

splunk | Server-Side Request Forgery
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-76273 — Improper Input Validation through the collect Command in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to add…

splunk | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-76272 — Missing Access Control through the REST API in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled pay…

splunk splunk_secure_gateway | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-76271 — Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Splunk Enterpr…

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause a denial of service against a Representationa…

splunk | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-76270 — Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available throu…

splunk | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-76269 — Improper Access Control in Search Job Retrieval through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantiall…

splunk | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-76268 — Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a s…

splunk | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-76267 — Log Injection through the REST API in Splunk App for Splunk O11y Cloud

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could inject forged entries into the app log through the Representation…

splunk | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.7 HIGH
CVE-2026-76266 — Local Privilege Escalation through Linux Package Upgrades in Splunk Enterprise

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package…

splunk | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-76265 — Improper Access Control through REST API Endpoints in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk r…

splunk splunk_secure_gateway | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-76264 — Improper Authorization through the REST API in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw conf…

splunk | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-1403 — Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that when importing CSV files could have allowed an authent…

gitlab | Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.1 MEDIUM
CVE-2026-107363 — OpenStack Zaqar Improper Authorization Vulnerability

In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a …

Remote | Authorization
Oct 07, 2026 Oct 08, 2026
Oct 07, 2026
Oct 08, 2026
7.7 HIGH
CVE-2026-107352 — Missing authorization checks in Amazon Athena engine version 3 request handling

Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.0 MEDIUM
CVE-2026-107229 — AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossin…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely vali…

Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.8 MEDIUM
CVE-2026-107228 — AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHea…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store repl…

Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15516 Results