Tag
Splunk Path Traversal Vulnerability Allows Arbitrary File Writes (CVE-2026-20297)
3 TTPs 1 CVEA path traversal vulnerability (CVE-2026-20297) in Splunk Enterprise and Splunk Cloud Platform allows an authenticated user with `edit_local_apps` and `install_apps` capabilities to write files outside the intended application directory during app installation, specifically into the `$SPLUNK_HOME/etc/` directory and its subdirectories, leading to configuration manipulation, persistence, or privilege escalation.
Splunk Enterprise and Cloud Platform CSRF Vulnerability Leading to Arbitrary SPL Execution (CVE-2026-20296)
4 TTPs 3 CVEsA Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2026-20296, in Splunk Enterprise and Splunk Cloud Platform allows an attacker to trick a user with the `list_deployment_server` capability into executing arbitrary Search Processing Language (SPL) searches as the highly privileged `splunk-system-user`, potentially leading to unauthorized access of stored credentials and indexed data due to a lack of CSRF token validation and improper input neutralization.
Splunk Enterprise: Multiple Vulnerabilities
6 TTPsAttackers can exploit multiple, unspecified vulnerabilities in Splunk Enterprise to bypass security measures, disclose sensitive information, manipulate data, execute arbitrary code, and cause denial-of-service conditions, potentially leading to other unspecified impacts.
Splunk Code Injection via Custom Dashboard Leading to RCE (CVE-2022-43571)
1 TTP 1 CVEAn authenticated user can exploit CVE-2022-43571, a code injection vulnerability within Splunk Enterprise or Splunk Cloud's dashboard PDF generation component, leading to remote code execution (RCE) and potential compromise of the Splunk environment.
Splunk XSS Privilege Escalation via Custom URLs in Dashboard (CVE-2024-36992)
2 rules 1 TTP 1 CVEA critical cross-site scripting (XSS) vulnerability, identified as CVE-2024-36992, affects Splunk Enterprise and Splunk Cloud Platform, allowing attackers to achieve privilege escalation by exploiting custom URLs within Splunk dashboards via malicious POST requests to the `splunk_internal_metrics/data/ui/views` endpoint, leading to the creation of new user accounts with elevated access permissions on the Splunk server.
Splunk User Enumeration Attempt Detection
1 TTP 1 CVEAn attacker is attempting to enumerate valid Splunk usernames by repeatedly submitting failed authentication attempts from a single source, as detected by monitoring the `_audit` index for multiple login failures, which is a precursor to credential-based attacks like password spraying or brute force, potentially leading to unauthorized access and sensitive data exposure.
Splunk RCE via User XSLT Exploitation (CVE-2023-46214)
1 rule 1 TTP 1 CVEThis brief identifies potential remote code execution (RCE) attempts targeting Splunk servers by exploiting CVE-2023-46214, a vulnerability related to user-supplied Extensible Stylesheet Language Transformations (XSLT) that allows attackers to execute arbitrary code leading to full system compromise.
Splunk RCE Through Arbitrary File Write to Windows System Root
2 rules 3 TTPs 2 CVEsA critical vulnerability (CVE-2024-45731, CVE-2024-45733) in Splunk Enterprise for Windows versions below 9.3.0, 9.2.3, and 9.1.6 allows low-privileged users to perform arbitrary file writes to the Windows system root directory (C:\Windows\System32) when Splunk is installed on a separate drive, enabling remote code execution through insecure session storage configuration.
Splunk Authentication Token Exposure in Debug Logs (CVE-2024-29945)
1 rule 1 TTP 1 CVEA critical vulnerability, CVE-2024-29945, allows for the exposure of authentication tokens in debug logs within Splunk Enterprise and Splunk Cloud, enabling an attacker with access to internal log files to gain unauthorized access, exfiltrate data, and potentially achieve full compromise of the Splunk infrastructure if unpatched versions (prior to 9.2.1, 9.1.4, and 9.0.9 for Enterprise) are in use.
Windows Post Exploitation Risk Behavior Detection
2 rules 8 TTPsThis analytic identifies potential post-exploitation behaviors on a Windows system by monitoring multiple risk events and their associated MITRE ATT&CK tactics, indicating potential malicious actions following an initial compromise.
High-Risk Repository Activity in DevSecOps Environments
2 rules 1 TTPThis analytic identifies high-risk activities within repositories by correlating repository data with risk scores in DevSecOps environments, focusing on scores above 100 and sources with more than three occurrences to highlight potential vulnerabilities leading to data breaches or infrastructure compromise.
O365 BEC Email Hiding Rule Creation
2 rules 1 TTPThis analytic detects the creation of suspicious mailbox rules in Office 365, a common technique used in Business Email Compromise (BEC) to hide emails by identifying rules with short or nonsensical names, marking emails as read, or moving them to specific folders.
Splunk Releases Security Advisory Addressing Multiple Products
2 rulesSplunk released security advisories on May 20, 2026, addressing vulnerabilities in Splunk User Behavior Analytics, AppDynamics Agents, Universal Forwarder, Enterprise, Cloud Platform, and AI Toolkit, prompting users to apply necessary updates.
Splunk Enterprise and Cloud Platform Information Disclosure Vulnerability (CVE-2026-20239)
2 rules 2 TTPs 1 CVESplunk Enterprise and Cloud Platform versions prior to 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13 are vulnerable to information disclosure (CVE-2026-20239), allowing users with access to the `_internal` index to view sensitive data.
Splunk MCP Server App Cleartext Credential Exposure (CVE-2026-20205)
2 rules 1 TTP 1 CVEA user with access to the `_internal` index or the `mcp_tool_admin` capability in Splunk MCP Server app versions below 1.0.3 can view user session and authorization tokens in clear text, leading to potential credential compromise.
Splunk Remote Code Execution Vulnerability (CVE-2026-20204)
2 rules 2 TTPs 1 CVEA low-privileged user can achieve remote code execution in vulnerable Splunk Enterprise and Cloud Platform versions by uploading a malicious file to the `$SPLUNK_HOME/var/run/splunk/apptemp` directory.