VDB

GCVE-110-NCSC-2026-322

GCVE-110-NCSC-2026-322
Advisory PublishedCVSS 8.1/10
Vulnetix · Advisory published August 21, 2026
Certain versions of Splunk Enterprise prior to 10.4.1, 10.2.6, 10.0.9, and 9.4.14 contain a vulnerability in the dispatch archive download path allowing unauthenticated users to access sensitive session data via embedded reports.

Weaknesses (CWE)

CWE-862Missing AuthorizationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-943Improper Neutralization of Special Elements in Data Query LogicCWE-321Use of Hard-coded Cryptographic KeyCWE-732Incorrect Permission Assignment for Critical ResourceCWE-639Authorization Bypass Through User-Controlled KeyCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-94Improper Control of Generation of Code ('Code Injection')CWE-26Path Traversal: '/dir/../filename'CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-352Cross-Site Request Forgery (CSRF)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-863Incorrect AuthorizationCWE-27Path Traversal: 'dir/../../filename'CWE-918Server-Side Request Forgery (SSRF)CWE-24Path Traversal: '../filedir'CWE-158Improper Neutralization of Null Byte or NUL CharacterCWE-306Missing Authentication for Critical Function

Risk Scores

CVSS 3.1
8.1/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Splunkvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

417 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›