# ANSSI warns of multiple Splunk vulnerabilities

Published: 2026-07-16 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/23c82bd0-21ac-597c-8453-18e5bff5778f/anssi-warns-of-multiple-splunk-vulnerabilities

> ANSSI advisory details numerous vulnerabilities in Splunk Enterprise, Cloud Platform, and Universal Forwarder that can lead to data confidentiality/integrity breaches and CSRF attacks.

CERT-FR has published an advisory covering multiple vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and Splunk Universal Forwarder across several version branches. The flaws, disclosed by Splunk in security bulletins SVD-2026-0702 through SVD-2026-0706 (dated 15 July 2026), collectively enable attackers to compromise data confidentiality, data integrity, and to conduct cross-site request forgery (CSRF) attacks against affected instances.

The advisory lists a large number of CVEs spanning the affected product lines, with no single vulnerability singled out as under active exploitation. Affected versions include Splunk Cloud Platform 10.1.2507.x through 10.5.2605.x, Splunk Enterprise 9.3.x through 10.4.x, and Splunk Universal Forwarder 9.4.x through 10.4.x, all below specific patched builds. Organizations running Splunk should consult the vendor bulletins and apply the corresponding patches to remediate the identified issues.

No indicators of compromise, threat actor attribution, or evidence of in-the-wild exploitation are provided in this advisory; it is a vendor patch notification distributed via the French national CERT.

## Mentioned in this report

- Vulnerabilities: CVE-2025-30204, CVE-2025-47913, CVE-2025-61726, CVE-2026-20296, CVE-2026-20297, CVE-2026-20298, CVE-2026-24051, CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-29181, CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVE-2026-32285, CVE-2026-32287, CVE-2026-34986, CVE-2026-39836, CVE-2026-39882, CVE-2026-39883, CVE-2026-42501, CVE-2026-6914, CVE-2026-6915, CVE-2026-8053, CVE-2026-8199, CVE-2026-8200, CVE-2026-8201, CVE-2026-8202

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0888

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/23c82bd0-21ac-597c-8453-18e5bff5778f/anssi-warns-of-multiple-splunk-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
