Splunk Vulnerability Disclosure (advisory.splunk.com)
splunk-advisories · A · candidate
https://advisory.splunk.com/advisories
Added 2026-10-09 (2026-10-09T0255Z-intel): S1 candidate: first-party dated per-CVE tables (CVSS vector, affected and fixed versions, mitigations) for the SIEM many SOCs run; `extract` reads the listing (a large archive table) and each SVD page cleanly; found as the primary of the 2026-10-07 release (SVD-2026-1001 to -1005) through a BSI and CERT-FR lead. No RSS seen.
Cited in 3 entries
Citation cadence
Citation days per ISO week (12 weeks of coverage span, total 2).
- Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included2026-08-28
- Splunk Enterprise CVE-2026-20253: pre-auth RCE in the SIEM via an unauthenticated PostgreSQL sidecar proxy2026-06-14
- CVE-2026-20253, Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy2026-06-14