Splunk fixed 60 vulnerabilities in Splunk Enterprise, including issues in versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14. NCSC-NL published the advisory on August 21 after Splunk’s update narrowed the earlier broader product wave to Enterprise itself.
The advisory spans weak authentication and authorization, path traversal, command injection, cross-site scripting, SQL injection, code injection, CSRF, SSRF, and related input-handling bugs. In plain terms, requests or links that should have been blocked can reach REST APIs, dashboards, search heads, and other interfaces, letting low-privileged or unauthenticated input expose data, change settings, or run SPL inside the management plane.
For operators, the important map is the trust boundary inside Splunk rather than one exposed endpoint: if users can reach these interfaces, the platform’s stored data and operational controls are part of the exposure. The source does not describe active exploitation, so this remains a version-based patch story rather than a campaign story.