Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▲ 27 respecto a la semana anterior
Críticas / altas1477▲ 294 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
398 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.19% | — | Splunk On-call | 19/8/2026 | 24/8/2026 | In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does… | |
| Analizada | Crítica (9.1) | 0.75% | — | Splunk Model Context Protocol Server | 19/8/2026 | 24/8/2026 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking… | |
| Analizada | Alta (7.4) | 0.24% | — | Splunk Connect FOR Kafka | 19/8/2026 | 24/8/2026 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because… | |
| Analizada | Alta (8.2) | 0.41% | — | Splunk Connect FOR Kafka | 19/8/2026 | 24/8/2026 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the connector to send authentication credentials… | |
| Analizada | Media (5.9) | 0.38% | — | Splunk Connect FOR Kafka | 19/8/2026 | 24/8/2026 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event delivery for the… | |
| Analizada | Media (5.9) | 0.38% | — | Splunk Connect FOR Kafka | 19/8/2026 | 24/8/2026 | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches… | |
| Analizada | Alta (8.1) | 0.35% | — | Splunk AI Toolkit | 19/8/2026 | 26/8/2026 | In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is… | |
| Analizada | Media (4.3) | 0.25% | — | Splunk AI Toolkit | 19/8/2026 | 24/8/2026 | In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history… | |
| Analizada | Alta (8.1) | 0.35% | — | Splunk AI Toolkit | 19/8/2026 | 21/8/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes… | |
| Analizada | Alta (7.5) | 0.32% | — | Splunk AI Toolkit | 19/8/2026 | 21/8/2026 | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as… | |
| Analizada | Alta (8.8) | 0.65% | — | Splunk AI Toolkit | 19/8/2026 | 26/8/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix… | |
| Analizada | Alta (8.3) | 0.35% | — | Splunk AI Toolkit | 19/8/2026 | 26/8/2026 | In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because… | |
| Analizada | Media (5.9) | 0.18% | — | Splunk AI Toolkit | 19/8/2026 | 26/8/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model lookup entry to reference attacker-controlled content. The race condition is possible because Splunk… | |
| Analizada | Media (5.4) | 0.23% | — | Splunk AI Toolkit | 19/8/2026 | 26/8/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores credentials for connected container… | |
| En análisis | Alta (8.3) | 0.47% | — | Splunk AI Toolkit | 19/8/2026 | 26/8/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege… | |
| Analizada | Alta (8.1) | 0.35% | — | Splunk Enterprise Security | 19/8/2026 | 25/8/2026 | In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all relevant data and system integrity through… | |
| Analizada | Alta (8.1) | 0.40% | — | Splunk Enterprise Security | 19/8/2026 | 25/8/2026 | In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Zoom APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are… | |
| Pendiente de análisis | Media (4.3) | 0.12% | — | Venafi APP FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked and are shown in cleartext in the user… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Attack Analyzer Connector FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password parameter is not masked and is shown in… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | RSA Securid Authentication ManagerAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Splunk PhantomAI | 19/8/2026 | 20/8/2026 | In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking the deflate item action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The information… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | MS Graph FOR Active Directory APP FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Crowdstrike Oauth API APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Cisco Webex APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The… |