Known Vulnerabilities for Enterprise Search by Elastic
Listed below are 4 of the newest known vulnerabilities associated with "Enterprise Search" by "Elastic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-76396 json | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a schedul... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76391 json | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches wi... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-76388 json | In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could ch... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-76387 json | In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_i... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-76354 json | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splun... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76353 json | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splun... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76350 json | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search cap... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-76349 json | In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user int... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76348 json | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76347 json | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.... | Not Provided | 2026-08-19 | 2026-08-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elastic | Enterprise Search | 7.9.0 | |||
| Application | Elastic | Enterprise Search | 7.8.1 | |||
| Application | Elastic | Enterprise Search | 7.8.0 | |||
| Application | Elastic | Enterprise Search | 7.7.1 | |||
| Application | Elastic | Enterprise Search | 7.7.0 | |||
| Application | Elastic | Enterprise Search | - |