ANSSI warns of multiple Splunk vulnerabilities
ANSSI advisory details numerous vulnerabilities in Splunk Enterprise, Cloud Platform, and Universal Forwarder that can lead to data confidentiality/integrity breaches and CSRF attacks.
CERT-FR has published an advisory covering multiple vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and Splunk Universal Forwarder across several version branches. The flaws, disclosed by Splunk in security bulletins SVD-2026-0702 through SVD-2026-0706 (dated 15 July 2026), collectively enable attackers to compromise data confidentiality, data integrity, and to conduct cross-site request forgery (CSRF) attacks against affected instances.
The advisory lists a large number of CVEs spanning the affected product lines, with no single vulnerability singled out as under active exploitation. Affected versions include Splunk Cloud Platform 10.1.2507.x through 10.5.2605.x, Splunk Enterprise 9.3.x through 10.4.x, and Splunk Universal Forwarder 9.4.x through 10.4.x, all below specific patched builds. Organizations running Splunk should consult the vendor bulletins and apply the corresponding patches to remediate the identified issues.
No indicators of compromise, threat actor attribution, or evidence of in-the-wild exploitation are provided in this advisory; it is a vendor patch notification distributed via the French national CERT.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0888
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free