Multiple vulnerabilities were identified in Splunk products. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system. Impact Remote Code Execution Denial of Service Information Disclosure Elevation of Privilege Security Restriction Bypass Cross-Site Scripting System / Technologies affected Splunk Enterprise 9.4 versions 9.4.0 to 9.4.13 Splunk Enterprise 10.0 versions 10.0.0 to 10.0.8 Splunk Enterprise 10.2 versions 10.2.0 to 10.2.5 Splunk Enterprise 10.4 versions 10.4.0 to 10.4.1 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://advisory.splunk.com/advisories/SVD-2026-0801
Multiple vulnerabilities in Splunk Enterprise, including remote code execution, denial of service, and privilege escalation, can be exploited by a remote attacker. Affected versions are Splunk Enterprise 9.4.0 to 9.4.13, 10.0.0 to 10.0.8, 10.2.0 to 10.2.5, and 10.4.0 to 10.4.1. Administrators must apply the fixes provided by Splunk via their security advisory portal.