# NCSC-NL Details 22 Splunk Enterprise Flaws

Published: 2026-10-09 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/1c6d4977-de76-56db-8c8f-faff3858a5e8/ncsc-nl-details-22-splunk-enterprise-flaws

> Splunk patched 22 vulnerabilities in Splunk Enterprise and Secure Gateway, including a 9.8-severity authentication bypass; no in-the-wild exploitation reported.

NCSC-NL published an advisory (NCSC-2026-0412) summarizing 22 CVEs that Splunk has fixed across multiple recent versions of Splunk Enterprise, with some issues also affecting Splunk Secure Gateway. The flaws span a broad range of weakness classes: insufficient authorization checks on REST API endpoints that let non-privileged users reach admin-level functionality or sensitive data, SQL injection in SPL2 modules, index-name manipulation, forged/injected log data, and a privilege-escalation path during package upgrades on Linux caused by trusting manipulated installation content. Additional issues include exposure of source code for the Discover Splunk Observability Cloud app via embedded source maps, bypass of restrictions on internal indexes, unauthorized modification of alert data and mobile recipient configuration stored in key-value stores, and a trailing-dot username issue that causes configuration data to be shared between accounts.

CVSS scores range from 4.1 up to 9.8, with several in the 6.3–8.8 range, indicating a mix of low-privilege information disclosure and higher-impact authorization/authentication bypass conditions. The advisory does not indicate active exploitation in the wild; it is a standard patch notification. Splunk has released updates addressing all listed CVEs. Defenders running Splunk Enterprise or Secure Gateway should review their deployed versions against Splunk's official security advisories, prioritize patching instances exposed to untrusted users (especially the CVE-2026-76268 authentication-bypass issue and CVE-2026-76282, an 8.8-rated authorization/privilege issue), and audit for unusual REST API access patterns, unexpected configuration changes, or anomalous user accounts with trailing-dot usernames as part of post-patch verification.

As this is a vendor-patch rollup from a single CERT bulletin covering one product line, it should be treated as routine patch-management guidance rather than evidence of an active campaign.

## Mentioned in this report

- Vulnerabilities: CVE-2026-76264, CVE-2026-76265, CVE-2026-76266, CVE-2026-76267, CVE-2026-76268, CVE-2026-76269, CVE-2026-76270, CVE-2026-76271, CVE-2026-76272, CVE-2026-76273, CVE-2026-76274, CVE-2026-76275, CVE-2026-76276, CVE-2026-76277, CVE-2026-76278, CVE-2026-76279, CVE-2026-76280, CVE-2026-76281, CVE-2026-76282, CVE-2026-76283, CVE-2026-76284, CVE-2026-76285

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0412.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1c6d4977-de76-56db-8c8f-faff3858a5e8/ncsc-nl-details-22-splunk-enterprise-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
