Skip to content
Multiple Vulnerabilities Discovered in Splunk Products Affecting Security Integrity

Multiple Vulnerabilities Discovered in Splunk Products Affecting Security Integrity

First seen 20 Aug 2026, 19:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 21, 2026 at 19:48 UTC
  • •Splunk disclosed multiple vulnerabilities across its products with CVSS scores up to 8.1.
  • •CVE-2026-76338 and CVE-2026-76364 allow unauthorized access and SQL injection, respectively.
  • •Organizations are urged to upgrade to the latest versions to mitigate these vulnerabilities.

Splunk has disclosed several vulnerabilities affecting its products, including Splunk Enterprise, SOAR, and AI Toolkit. Key vulnerabilities include CVE-2026-76338, CVE-2026-76352, CVE-2026-76362, CVE-2026-76364, and CVE-2026-76399, with CVSS scores ranging from 6.5 to 8.1. Attack vectors include unauthorized access through REST API exploitation, Cross-Site Scripting (XSS), and SQL injection. Affected systems include Splunk Enterprise versions below 10.4.2 and Splunk SOAR versions below 8.6.0. Users are advised to upgrade to the latest versions to mitigate risks. Current reports indicate no public proof-of-concept exploits, but the vulnerabilities pose significant risks to data confidentiality and system integrity. Organizations should audit their configurations and restrict roles to trusted users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-08-19
CVE-2026-76338 published
A vulnerability in Splunk Enterprise allows unauthorized access to Splunk Observability Cloud data.
advisory.splunk.com
2026-08-19
CVE-2026-76352 published
Cross-Site Scripting vulnerability in Splunk Enterprise could allow unauthorized JavaScript execution.
advisory.splunk.com
2026-08-19
CVE-2026-76362 published
Vulnerability in Splunk SOAR allows unauthenticated users to execute arbitrary code via REST API.
advisory.splunk.com
2026-08-19
CVE-2026-76364 published
SQL injection vulnerability in Splunk SOAR allows arbitrary SQL execution by authenticated users.
Feedly
2026-08-19
CVE-2026-76399 published
Vulnerability in Splunk AI Toolkit allows users to modify scheduled searches to run arbitrary SPL commands.
Feedly

More articles in this cluster (11)

Following this threat?

Track CVE-2026-76338 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed