NCSC-NL said Splunk fixed 22 vulnerabilities in Splunk Enterprise and some Splunk Secure Gateway versions on Oct. 9, spanning several recent release lines. The advisory includes three critical and three high-severity issues among the set.
Several of the bugs are trust-boundary failures: REST API endpoints did not always check authorization correctly, so non-admin users could reach privileged functions or sensitive data, view other users' searches and log data, change configuration, sign payloads, or tamper with alert and mobile receiver data. Other flaws cover SQL injection in SPL2 modules, forged log data, and a Linux package-upgrade path that can turn manipulated install content into privilege escalation.
For Splunk operators, the exposure is not confined to one feature or one branch; it sits wherever low-privilege access can touch search, jobs, signing, or upgrade paths. If Splunk is part of your logging or platform layer, the lingering question is which deployed instance still inherits one of these server-side trust failures.