news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans les produits Splunk (16 juillet 2026)

High
Summary

Multiple vulnerabilities have been discovered in Splunk products, including Splunk Cloud Platform and Enterprise versions. These vulnerabilities allow for data confidentiality and integrity breaches, as well as the potential for Cross-Site Request Forgery (CSRF) attacks. The affected products range from versions 10.0 to 10.5, and the vulnerabilities are associated with CVE-2025-30204 through CVE-2026-8202. Users are advised to refer to the Splunk security advisories for detailed information and to apply the necessary patches immediately.

Multiple vulnerabilities have been discovered in Splunk products, including Splunk Cloud Platform and Enterprise versions. These vulnerabilities allow for data confidentiality and integrity breaches, as well as the potential for Cross-Site Request Forgery (CSRF) attacks. The affected products range from versions 10.0 to 10.5, including Splunk Cloud Platform versions 10.1.2507.x through 10.1.2507.24, 10.2.2510.x through 10.2.2510.18, 10.3.2512.x through 10.3.2512.16, 10.4.2604.x through 10.4.2604.7, and 10.5.2605.x through 10.5.2605.0. Additionally, Splunk Enterprise versions 10.0.x through 10.0.8, 10.2.x through 10.2.5, 10.4.x through 10.4.1, and 9.3.x through 9.3.14, as well as Splunk Universal Forwarder versions 10.0.x through 10.0.8, 10.2.x through 10.2.5, and 10.4.x through 10.4.1, are also impacted. The vulnerabilities are associated with CVE-2025-30204, CVE-2025-47913, CVE-2025-61726, CVE-2026-20296, CVE-2026-20297, CVE-2026-20298, CVE-2026-24051, CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-29181, CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVE-2026-32285, CVE-2026-32287, CVE-2026-34986, CVE-2026-39836, CVE-2026-39882, CVE-2026-39883, CVE-2026-42501, CVE-2026-6914, CVE-2026-6915, CVE-2026-8053, CVE-2026-8199, CVE-2026-8200, CVE-2026-8201, and CVE-2026-8202. Users are advised to refer to the Splunk security advisories for detailed information and to apply the necessary patches immediately.

Read the full article at CERT-FR