Third-Party Package Updates in Splunk Universal Forwarder - April 2026

Advisory ID: SVD-2026-0404

CVE ID: CVE-2026-22796

Published: 2026-04-15

Last Update: 2026-04-15

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Universal Forwarder versions 10.2.1, 10.0.4, 9.4.10, 9.3.11, and higher.

PackageRemediationCVESeverity
OpenSSL1Upgraded OpenSSL to version 1.0.2zoCVE-2026-22796Low

1 Upgraded OpenSSL to version 1.0.2zo to remedy CVE-2026-22796 at $SPLUNK_HOME/lib/libcrypto.so.1.0.0 and $SPLUNK_HOME/lib/libssl.so.1.0.0

Solution

Upgrade Splunk Universal Forwarder to versions 10.2.1, 10.0.4, 9.4.10, 9.3.11, or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk Universal Forwarder10.210.2.010.2.1
Splunk Universal Forwarder9.410.0.0 to 10.0.310.0.4
Splunk Universal Forwarder9.49.4.0 to 9.4.99.4.10
Splunk Universal Forwarder9.39.3.0 to 9.3.109.3.11

Severity

For CVE-2026-22796, Splunk adopted the vendor’s severity rating.