Frequency
1
occurrences
First Seen
August 20, 2026
Last Seen
August 20, 2026
Related Threat Clusters
-
Multiple Vulnerabilities Discovered in Splunk Products
Splunk has addressed several vulnerabilities affecting its Enterprise and SOAR products. CVE-2026-76338 and CVE-2026-76352 allow unauthorized access to Splunk Observability Cloud data and potential system integrity…
2 articles · Updated August 20, 2026
Recent Intelligence Reports
- SVD-2026-0804: Security Hardening Release for Splunk SOAR - August 2026 Splunk Security Announcements / 19h In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer’s archive extraction to write files outside the intended inst — advisory.splunk.com · August 20, 2026
Related Entities
Arbitrary Code Execution
Authentication Bypass
Denial of Service
Information Disclosure
Server-Side Request Forgery (ssrf)
Sql Injection
CVE-2026-76362
CWE-200 - Exposure of Sensitive Information
CWE-22 - Path Traversal
CWE-287 - Improper Authentication
Cwe-79 - Cross-site Scripting (xss)
CWE-862 - Missing Authorization