Third-Party Package Updates in Splunk Universal Forwarder - April 2026
Advisory ID: SVD-2026-0404
CVE ID: CVE-2026-22796
Published: 2026-04-15
Last Update: 2026-04-15
Description
Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Universal Forwarder versions 10.2.1, 10.0.4, 9.4.10, 9.3.11, and higher.
| Package | Remediation | CVE | Severity |
|---|---|---|---|
| OpenSSL1 | Upgraded OpenSSL to version 1.0.2zo | CVE-2026-22796 | Low |
1 Upgraded OpenSSL to version 1.0.2zo to remedy CVE-2026-22796 at $SPLUNK_HOME/lib/libcrypto.so.1.0.0 and $SPLUNK_HOME/lib/libssl.so.1.0.0
Solution
Upgrade Splunk Universal Forwarder to versions 10.2.1, 10.0.4, 9.4.10, 9.3.11, or higher.
Product Status
| Product | Base Version | Affected Version | Fix Version |
|---|---|---|---|
| Splunk Universal Forwarder | 10.2 | 10.2.0 | 10.2.1 |
| Splunk Universal Forwarder | 9.4 | 10.0.0 to 10.0.3 | 10.0.4 |
| Splunk Universal Forwarder | 9.4 | 9.4.0 to 9.4.9 | 9.4.10 |
| Splunk Universal Forwarder | 9.3 | 9.3.0 to 9.3.10 | 9.3.11 |
Severity
For CVE-2026-22796, Splunk adopted the vendor’s severity rating.