VDB

GCVE-110-NCSC-2026-412

GCVE-110-NCSC-2026-412
Advisory PublishedCVSS 7.6/10
Vulnetix · Advisory published October 9, 2026
Certain versions of Splunk Enterprise prior to 10.4.2, 10.2.6, 10.0.10, and 9.4.15 contain a vulnerability allowing non-admin or non-power users to create or edit scripted lookup definitions via raw configuration endpoints due to missing external lookup capability checks.

Weaknesses (CWE)

CWE-863Incorrect AuthorizationCWE-117Improper Output Neutralization for LogsCWE-306Missing Authentication for Critical FunctionCWE-639Authorization Bypass Through User-Controlled KeyCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-407Inefficient Algorithmic ComplexityCWE-862Missing AuthorizationCWE-918Server-Side Request Forgery (SSRF)CWE-1188Initialization of a Resource with an Insecure DefaultCWE-732Incorrect Permission Assignment for Critical Resource

Risk Scores

CVSS 3.1
7.6/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Affected Products

VendorProductVersionsPlatforms
Splunkvers:unknown/*——

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,380 records in the GCVE database · Updated October 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›