Multiple Vulnerabilities Discovered in Splunk Products
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
Splunk has addressed several vulnerabilities affecting its Enterprise and SOAR products. CVE-2026-76338 and CVE-2026-76352 allow unauthorized access to Splunk Observability Cloud data and potential system integrity issues via XSS attacks. Additionally, CVE-2026-76364, a SQL injection vulnerability in Splunk SOAR, enables authenticated users to execute arbitrary SQL commands. Affected versions include Splunk Enterprise versions below 10.4.2 and Splunk SOAR versions below 8.6.0. Users are advised to upgrade to the latest versions and restrict access to sensitive roles. The vulnerabilities were published on August 19, 2026, with no evidence of active exploitation reported yet.
Key Points: • CVE-2026-76338 allows unauthorized access to Splunk Observability Cloud data. • CVE-2026-76364 enables SQL injection attacks for authenticated users in Splunk SOAR. • Users should upgrade to the latest Splunk versions and restrict sensitive role access.