Third-Party Package Updates in Splunk Enterprise - June 2026
Advisory ID: SVD-2026-0610
CVE ID: Multiple
Published: 2026-06-10
Last Update: 2026-06-10
Description
Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Enterprise versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, 9.3.13, and higher.
| Package | Remediation | CVE | Severity |
|---|---|---|---|
| golang1 | Upgraded golang to Go compiler in `compsup` binary to version go1.26.1 | Multiple | Critical |
| MongoDB2 | Upgraded MongoDB version 7.0.30 to version 7.0.31 and MongoDB version 8.0.19 to version 8.0.20 | Multiple | High |
| aiohttp3 | Upgraded aiohttp to version 3.13.5 | Multiple | Critical |
| go.opentelemetry.io/otel/sdk4 | Upgraded opentelemetry to version 1.43.0 | CVE-2026-24051 | High |
| PostgreSQL5 | Upgraded postgresql to version 17.8 | Multiple | High |
| golang.org/x/crypto6 | Upgraded golang crypto in `etcd, etcdctl, and etcdutl` binaries to version 0.48.0 | Multiple | High |
| apache-log4j7 | Upgraded apache-log4j version 2.17.2 to version 2.25.4 | Multiple | Medium |
| cloudflare/circl8 | Upgraded cloudflare/circl in `compsup` binary to version 1.6.3 | CVE-2026-1229 | Low |
| cloudflare/circl9 | Upgraded cloudflare/circl in `splunk-supervisor` binary to version 1.6.3 | CVE-2026-1229 | Low |
1 Upgraded golang in compsup binary to Go compiler version go1.26.1 to remedy CVE-2025-68121, CVE-2025-61732, CVE-2025-61731, CVE-2025-61726, CVE-2026-25679, CVE-2026-27142 at /opt/splunk/bin/compsupin Splunk Enterprise 10.4.0 and 9.3.13. The fix was already applied in prior Splunk Enterprise versions 10.2.3, 10.0.6, and 9.4.11.
2 For Splunk Enterprise versions 9.4.12 and 10.0.7 for Linux and Windows, Splunk Enterprise upgraded MongoDB 7.0.30 to version 7.0.31 at $SPLUNK_HOME/bin/mongodto remedy CVE-2026-4147, CVE-2026-4148 and CVE-2026-4358.
For Splunk Enterprise versions 10.2.4 for Linux and Windows, Splunk Enterprise upgraded MongoDB 8.0.19 to version 8.0.20 at $SPLUNK_HOME/bin/mongodto remedy CVE-2026-4147, CVE-2026-4148 and CVE-2026-4358.
For Splunk Enterprise version 10.4.0 for Linux and Windows, Splunk Enterprise upgraded MongoDB 7.0.30 to version 7.0.31 and MongoDB 8.0.19 to version 8.0.20 at $SPLUNK_HOME/bin/mongodto remedy CVE-2026-4147, CVE-2026-4148 and CVE-2026-4358.
3 Upgraded aiohttp to version 3.13.5 to remedy CVE-2026-34516 and CVE-2026-34520 at $SPLUNK_HOME/etc/apps/splunk_secure_gateway/lib/aiohttp-3.13.3.dist-info/METADATAin Splunk Enterprise versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13. The fix is applied in Splunk Secure Gateway app versions 3.10.6, 3.9.20 and 3.8.67.
4 Upgraded opentelemetry to version 1.43.0 to remedy CVE-2026-24051 at $SPLUNK_HOME/packages/cmp-orchestrator-1.264.19+126da777-20260319t073336.tar.gz/splunk-cmp-orchestratorin Splunk Enterprise versions 10.4.0, 10.2.4 and 10.0.7. Splunk Enterprise versions 9.4.x and 9.3.x are not affected.
5 Upgraded postgresql to version 17.8 to remedy CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, and CVE-2026-2006 in Splunk Enterprise versions 10.4.0, 10.2.4 and 10.0.7. The Postgres sidecar is not present in Splunk Enterprise versions 9.4.x and 9.3.x.
6 Upgraded golang crypto in etcd, etcdctl, and etcdutl binaries to version 0.48.0 to remedy CVE-2025-47913, CVE-2025-58181, and CVE-2025-47914 in Splunk Enterprise versions 10.4.0 and 10.2.4. The etcd, etcdctl, and etcdutl binaries are not present in Splunk Enterprise versions 10.0.x, 9.4.x, 9.3.x.
7 Upgraded apache-log4j to version 2.25.4 to remedy CVE-2025-68161, CVE-2026-34480, CVE-2026-34477 in Splunk Enterprise versions 10.0.7, 9.4.12 and 9.3.13. Splunk Enterprise versions 10.2.x and 10.4.x does not have apache-log4j.
8 Upgraded cloudflare/circl in compsupbinary to version 1.6.3 to remedy CVE-2026-1229 at /opt/splunk/bin/compsup in Splunk Enterprise version 9.3.13. The fix was applied in prior Splunk Enterprise versions 10.0.6 and 9.4.11.
9 Upgraded cloudflare/circl in splunk-supervisorbinary to version 1.6.3 to remedy CVE-2026-1229 at /opt/splunk/bin/splunk-supervisor in Splunk Enterprise versions 10.4.0 and 10.2.4.
Note for items 8 and 9: The affected binary name changed across Splunk Enterprise versions. In earlier Splunk Enterprise versions 10.0.x, 9.4.x and 10.3.x, this component is referenced as compsup at /opt/splunk/bin/compsup. In later Splunk Enterprise versions 10.2.x and 10.4.0, the same component is referenced as splunk-supervisor at /opt/splunk/bin/splunk-supervisor.
Solution
Upgrade Splunk Enterprise to versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, 9.3.13, or higher.
Product Status
| Product | Base Version | Affected Version | Fix Version |
|---|---|---|---|
| Splunk Enterprise | 10.4 | Below 10.4.0 | 10.4.0 |
| Splunk Enterprise | 10.2 | 10.2.0 to 10.2.3 | 10.2.4 |
| Splunk Enterprise | 10.0 | 10.0.0 to 10.0.6 | 10.0.7 |
| Splunk Enterprise | 9.4 | 9.4.0 to 9.4.11 | 9.4.12 |
| Splunk Enterprise | 9.3 | 9.3.0 to 9.3.12 | 9.3.13 |
Severity
For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.