securityonline.info 8/20/2026, 5:16:21 AM · external

Splunk patches 60 flaws, three critical CVSS 9.4 bugs expose data

Splunk patches 60 flaws, three critical CVSS 9.4 bugs expose data
CyberSIXT Evidence Panel
Primary Source advisory.splunk.com

ON August 19, 2026, Splunk resolved 60 vulnerabilities within its Splunk Enterprise software, with three critical flaws assigned a CVSS score of 9.4. These vulnerabilities allow unauthenticated users to access sensitive data and affect system integrity. No confirmed exploits were reported in the wild. The critical flaws include improper access control mechanisms regarding embedded report tokens, enabling attackers to obtain session data from the API.

Users are advised to upgrade to the latest versions (10.4.2, 10.2.6, 10.0.9, or 9.4.14) and apply security configurations to mitigate these vulnerabilities.

View Primary Source Via securityonline.info

Article by CyberSIXT