VYPR

Monitoring Console app

by Splunk

CVEs (3)

  • CVE-2022-27183HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.01

    The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4. The Monitoring Console app is a bundled app included in Splunk Enterprise, not for download on SplunkBase, and not installed on…

  • CVE-2026-76329MedAug 19, 2026
    risk 0.42cvss 6.4epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role into opening a crafted link to Monitoring Console. When that user opens the link, Splunk Enterprise runs attacker-controlled…

  • CVE-2026-20141MedFeb 18, 2026
    risk 0.28cvss 4.3epss 0.00

    In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access the Splunk Monitoring Console App endpoints due to an improper access control. This could lead to a sensitive information…