VendorsSplunksplunk_secure_gatewayany version
Vulnerabilities

Splunk Secure Gateway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2026-20251
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
Published 2026-06-10 · Analyzed
8.8EPSS 0.322
CVE-2026-76351
Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway
Published 2026-08-19 · Analyzed
8.8EPSS 0.004
CVE-2025-20231
Sensitive Information Disclosure in Splunk Secure Gateway App
Published 2025-03-26 · Analyzed
7.1EPSS 0.005
CVE-2025-20389
Improper Input Validation in "label" column field in Splunk Secure Gateway App
Published 2025-12-03 · Analyzed
6.5EPSS 0.004
CVE-2026-76257
Missing Authorization through REST API Endpoints in Splunk Secure Gateway
Published 2026-08-19 · Analyzed
6.5EPSS 0.003
CVE-2026-76258
Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway
Published 2026-08-19 · Analyzed
6.5EPSS 0.003
CVE-2025-20230
Missing Access Control and Incorrect Ownership of Data in App Key Value Store (KVStore) collections in the Splunk Secure Gateway App
Published 2025-03-26 · Analyzed
6.5EPSS 0.003
CVE-2026-76261
Insecure Default Access Control List through the REST API in Splunk Secure Gateway
Published 2026-08-19 · Analyzed
6.5EPSS 0.003
CVE-2026-76327
SPL Injection through Splunk Web in Splunk Secure Gateway
Published 2026-08-19 · Analyzed
6.4EPSS 0.003
CVE-2026-76347
Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway
Published 2026-08-19 · Analyzed
5.4EPSS 0.003
CVE-2025-20383
Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app
Published 2025-12-03 · Analyzed
4.3EPSS 0.003
CVE-2026-76256
Information Exposure through REST API Endpoints in Splunk Secure Gateway
Published 2026-08-19 · Analyzed
4.3EPSS 0.003