Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-76400 — Denial of Service (DoS) through the REST API in Splunk Connect for Kafka

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer …

Remote | Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-76399 — Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permission…

ai_toolkit | Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76398 — Improper Access Control during Experiment History Deletion through the REST API in Splunk…

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representati…

ai_toolkit | Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-76397 — Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vu…

ai_toolkit | Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-76396 — Improper Access Control through Scheduled Searches in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search co…

ai_toolkit | Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-76395 — Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loadin…

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. Th…

ai_toolkit | Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.3 HIGH
CVE-2026-76394 — Missing Authorization in Container and Connection Management through the REST API in Splu…

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and c…

ai_toolkit | Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.9 MEDIUM
CVE-2026-76393 — Race Condition during Model Upload through the REST API in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing …

ai_toolkit | Remote | Race Condition
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.4 MEDIUM
CVE-2026-76392 — Use of Hard-coded Credentials in Container Connections in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of ha…

ai_toolkit | Remote | Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.3 HIGH
CVE-2026-76391 — Improper Privilege Management through Agent Run History in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integr…

ai_toolkit | Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.3 MEDIUM
CVE-2026-76390 — Information Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Secu…

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-76389 — Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for E…

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligenc…

Remote | Server-Side Request Forgery
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-76388 — Privilege Escalation through Search Macro Permissions in Splunk Enterprise Security

In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that schedule…

enterprise_security | Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-76387 — SPL Injection through the REST API in Splunk Enterprise Security

In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL)…

enterprise_security | Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76386 — Information Disclosure through Action Parameters in Zoom app for Splunk SOAR

In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create me…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76385 — Information Disclosure through Action Parameters in Venafi app for Splunk SOAR

In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate actio…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76384 — Information Disclosure through Action Parameters in Splunk Attack Analyzer Connector for …

In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either th…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76383 — Information Disclosure through Action Parameters in RSA SecurID Authentication Manager ap…

In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either …

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76382 — Information Disclosure through Action Parameters in Phantom app for Splunk SOAR

In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking the deflate item action, becau…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76381 — Information Disclosure through Action Parameters in MS Graph for Active Directory app for…

In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset passwo…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Showing 20 of 12688 Results