ON August 19, 2026, Splunk resolved 60 vulnerabilities within its Splunk Enterprise software, with three critical flaws assigned a CVSS score of 9.4. These vulnerabilities allow unauthenticated users to access sensitive data and affect system integrity. No confirmed exploits were reported in the wild. The critical flaws include improper access control mechanisms regarding embedded report tokens, enabling attackers to obtain session data from the API.
Users are advised to upgrade to the latest versions (10.4.2, 10.2.6, 10.0.9, or 9.4.14) and apply security configurations to mitigate these vulnerabilities.