NCSC-NL Details 22 Splunk Enterprise Flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Splunk patched 22 vulnerabilities in Splunk Enterprise and Secure Gateway, including a 9.8-severity authentication bypass; no in-the-wild exploitation reported.
NCSC-NL published an advisory (NCSC-2026-0412) summarizing 22 CVEs that Splunk has fixed across multiple recent versions of Splunk Enterprise, with some issues also affecting Splunk Secure Gateway. The flaws span a broad range of weakness classes: insufficient authorization checks on REST API endpoints that let non-privileged users reach admin-level functionality or sensitive data, SQL injection in SPL2 modules, index-name manipulation, forged/injected log data, and a privilege-escalation path during package upgrades on Linux caused by trusting manipulated installation content. Additional issues include exposure of source code for the Discover Splunk Observability Cloud app via embedded source maps, bypass of restrictions on internal indexes, unauthorized modification of alert data and mobile recipient configuration stored in key-value stores, and a trailing-dot username issue that causes configuration data to be shared between accounts.
CVSS scores range from 4.1 up to 9.8, with several in the 6.3–8.8 range, indicating a mix of low-privilege information disclosure and higher-impact authorization/authentication bypass conditions. The advisory does not indicate active exploitation in the wild; it is a standard patch notification. Splunk has released updates addressing all listed CVEs. Defenders running Splunk Enterprise or Secure Gateway should review their deployed versions against Splunk's official security advisories, prioritize patching instances exposed to untrusted users (especially the CVE-2026-76268 authentication-bypass issue and CVE-2026-76282, an 8.8-rated authorization/privilege issue), and audit for unusual REST API access patterns, unexpected configuration changes, or anomalous user accounts with trailing-dot usernames as part of post-patch verification.
As this is a vendor-patch rollup from a single CERT bulletin covering one product line, it should be treated as routine patch-management guidance rather than evidence of an active campaign.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0412.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,134 reports from 148 sources, 493 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs