Third-Party Package Updates in Splunk Enterprise - June 2026

Advisory ID: SVD-2026-0610

CVE ID:  Multiple

Published: 2026-06-10

Last Update: 2026-06-10

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Enterprise versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, 9.3.13, and higher.

PackageRemediationCVESeverity
golang1Upgraded golang to Go compiler in `compsup` binary to version go1.26.1MultipleCritical
MongoDB2Upgraded MongoDB version 7.0.30 to version 7.0.31 and MongoDB version 8.0.19 to version 8.0.20MultipleHigh
aiohttp3Upgraded aiohttp to version 3.13.5MultipleCritical
go.opentelemetry.io/otel/sdk4Upgraded opentelemetry to version 1.43.0CVE-2026-24051High
PostgreSQL5Upgraded postgresql to version 17.8MultipleHigh
golang.org/x/crypto6Upgraded golang crypto in `etcd, etcdctl, and etcdutl` binaries to version 0.48.0MultipleHigh
apache-log4j7Upgraded apache-log4j version 2.17.2 to version 2.25.4MultipleMedium
cloudflare/circl8Upgraded cloudflare/circl in `compsup` binary to version 1.6.3CVE-2026-1229Low
cloudflare/circl9Upgraded cloudflare/circl in `splunk-supervisor` binary to version 1.6.3CVE-2026-1229Low

1 Upgraded golang in compsup binary to Go compiler version go1.26.1 to remedy CVE-2025-68121, CVE-2025-61732, CVE-2025-61731, CVE-2025-61726, CVE-2026-25679, CVE-2026-27142 at /opt/splunk/bin/compsupin Splunk Enterprise 10.4.0 and 9.3.13. The fix was already applied in prior Splunk Enterprise versions 10.2.3, 10.0.6, and 9.4.11.

2 For Splunk Enterprise versions 9.4.12 and 10.0.7 for Linux and Windows, Splunk Enterprise upgraded MongoDB 7.0.30 to version 7.0.31 at $SPLUNK_HOME/bin/mongodto remedy CVE-2026-4147, CVE-2026-4148 and CVE-2026-4358.

For Splunk Enterprise versions 10.2.4 for Linux and Windows, Splunk Enterprise upgraded MongoDB 8.0.19 to version 8.0.20 at $SPLUNK_HOME/bin/mongodto remedy CVE-2026-4147, CVE-2026-4148 and CVE-2026-4358.

For Splunk Enterprise version 10.4.0 for Linux and Windows, Splunk Enterprise upgraded MongoDB 7.0.30 to version 7.0.31 and MongoDB 8.0.19 to version 8.0.20 at $SPLUNK_HOME/bin/mongodto remedy CVE-2026-4147, CVE-2026-4148 and CVE-2026-4358.

3 Upgraded aiohttp to version 3.13.5 to remedy CVE-2026-34516 and CVE-2026-34520 at $SPLUNK_HOME/etc/apps/splunk_secure_gateway/lib/aiohttp-3.13.3.dist-info/METADATAin Splunk Enterprise versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13. The fix is applied in Splunk Secure Gateway app versions 3.10.6, 3.9.20 and 3.8.67.

4 Upgraded opentelemetry to version 1.43.0 to remedy CVE-2026-24051 at $SPLUNK_HOME/packages/cmp-orchestrator-1.264.19+126da777-20260319t073336.tar.gz/splunk-cmp-orchestratorin Splunk Enterprise versions 10.4.0, 10.2.4 and 10.0.7. Splunk Enterprise versions 9.4.x and 9.3.x are not affected.

5 Upgraded postgresql to version 17.8 to remedy CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, and CVE-2026-2006 in Splunk Enterprise versions 10.4.0, 10.2.4 and 10.0.7. The Postgres sidecar is not present in Splunk Enterprise versions 9.4.x and 9.3.x.

6 Upgraded golang crypto in etcd, etcdctl, and etcdutl binaries to version 0.48.0 to remedy CVE-2025-47913, CVE-2025-58181, and CVE-2025-47914 in Splunk Enterprise versions 10.4.0 and 10.2.4. The etcd, etcdctl, and etcdutl binaries are not present in Splunk Enterprise versions 10.0.x, 9.4.x, 9.3.x.

7 Upgraded apache-log4j to version 2.25.4 to remedy CVE-2025-68161, CVE-2026-34480, CVE-2026-34477 in Splunk Enterprise versions 10.0.7, 9.4.12 and 9.3.13. Splunk Enterprise versions 10.2.x and 10.4.x does not have apache-log4j.

8 Upgraded cloudflare/circl in compsupbinary to version 1.6.3 to remedy CVE-2026-1229 at /opt/splunk/bin/compsup in Splunk Enterprise version 9.3.13. The fix was applied in prior Splunk Enterprise versions 10.0.6 and 9.4.11.

9 Upgraded cloudflare/circl in splunk-supervisorbinary to version 1.6.3 to remedy CVE-2026-1229 at /opt/splunk/bin/splunk-supervisor in Splunk Enterprise versions 10.4.0 and 10.2.4.

Note for items 8 and 9: The affected binary name changed across Splunk Enterprise versions. In earlier Splunk Enterprise versions 10.0.x, 9.4.x and 10.3.x, this component is referenced as compsup  at /opt/splunk/bin/compsup. In later Splunk Enterprise versions 10.2.x and 10.4.0, the same component is referenced as  splunk-supervisor at /opt/splunk/bin/splunk-supervisor.

Solution

Upgrade Splunk Enterprise to versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, 9.3.13, or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk Enterprise10.4Below 10.4.010.4.0
Splunk Enterprise10.210.2.0 to 10.2.310.2.4
Splunk Enterprise10.010.0.0 to 10.0.610.0.7
Splunk Enterprise9.49.4.0 to 9.4.119.4.12
Splunk Enterprise9.39.3.0 to 9.3.129.3.13

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.