<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:53:04 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0736 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0736</link>
      <description>certfr-2026-avi-0736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0736</guid>
    </item>
    <item>
      <title>EUVD-2026-326552</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326552</link>
      <description>EUVD-2026-326552</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326552</guid>
    </item>
    <item>
      <title>fkie_cve-2026-20251</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-20251</link>
      <description>&lt;p&gt;In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the &amp;#39;admin&amp;#39; or &amp;#39;power&amp;#39; Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the &amp;#39;admin&amp;#39; or &amp;#39;power&amp;#39; Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-20251</guid>
    </item>
    <item>
      <title>GHSA-3crw-7xg9-fpxg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3crw-7xg9-fpxg</link>
      <description>&lt;p&gt;In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the &amp;#39;admin&amp;#39; or &amp;#39;power&amp;#39; Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the &amp;#39;admin&amp;#39; or &amp;#39;power&amp;#39; Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3crw-7xg9-fpxg</guid>
    </item>
    <item>
      <title>NCSC-2026-0198 — Kwetsbaarheden verholpen in Splunk Enterprise en Splunk Cloud Platform</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0198</link>
      <description>NCSC-2026-0198</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0198</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1877 — Splunk Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1877</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk Enterprise ausnutzen, um beliebigen Code auszuführen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk Enterprise ausnutzen, um beliebigen Code auszuführen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1877</guid>
    </item>
  </channel>
</rss>
