CVE Tools

Splunk Cloud Platform

119 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Splunk Cloud Platform, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Splunk Cloud Platform CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Splunk Cloud Platform CVEs per month
MonthCVEs
2024-106
2024-110
2024-123
2025-010
2025-020
2025-035
2025-040
2025-050
2025-061
2025-076
2025-080
2025-090
2025-106
2025-112
2025-126
2026-010
2026-023
2026-035
2026-043
2026-052
2026-068
2026-073
2026-080
2026-090

Severity

How the 119 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High4235%
  • Medium6756%
  • Low108%

Latest CVEs

The 15 most recently published vulnerabilities affecting Splunk Cloud Platform.

  1. CVE-2026-20298Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise5.3
  2. CVE-2026-20296SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise8.3
  3. CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise7.2
  4. CVE-2026-20258Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise7.1
  5. CVE-2026-20252Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise7.6
  6. CVE-2026-20257Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise5.7
  7. CVE-2026-20259Improper Access Control in Splunk Enterprise5.5
  8. CVE-2026-20251Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway8.8
  9. CVE-2026-20255Improper Input Validation through Classic Dashboards in Splunk Enterprise5.7
  10. CVE-2026-20254Information Disclosure through External Content Restriction Bypass in Splunk Enterprise5.7
  11. CVE-2026-20256Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise5.7
  12. CVE-2026-20239Sensitive Information Disclosure through Log Files in Splunk Enterprise7.5
  13. CVE-2026-20240Denial of Service through coldToFrozen.sh Script in Splunk Enterprise6.5
  14. CVE-2026-20203Improper Access Control in Data Model Acceleration in Splunk Enterprise4.3
  15. CVE-2026-20204Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise7.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store