Third-Party Package Updates in Splunk Enterprise - August 2026
Advisory ID: SVD-2026-0802
CVE ID:
Published: 2026-08-19
Last Update: 2026-08-19
Description
Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, 9.4.14, and higher.
| Package | Remediation | CVE | Severity |
|---|---|---|---|
| github.com/golang/go1 | Upgraded golang to Go compiler version 1.26.3 | Multiple | Critical |
| github.com/go-jose/go-jose/v42 | Upgraded go-jose in the ipc-broker binary to version 4.1.4 | CVE-2026-34986 | High |
| go.opentelemetry.io/otel3 | Upgraded opentelemetry/otel in ipc-broker to version 1.44.0 | CVE-2026-29181 | High |
| go.opentelemetry.io/otel/sdk4 | Upgraded opentelemetry/otel/sdk in ipc-broker to version 1.44.0 | CVE-2026-39883 | High |
| github.com/go-jose/go-jose/v45 | Upgraded go-jose in the splunk-topology sidecar to version 4.1.4 | CVE-2026-34986 | High |
| go.opentelemetry.io/otel6 | Upgraded opentelemetry/otel in splunk-topology to version 1.44.0 | CVE-2026-29181 | High |
| go.opentelemetry.io/otel/sdk7 | Upgraded opentelemetry/otel/sdk in splunk-topology to version 1.44.0 | CVE-2026-39883 | High |
| golang-go8 | Upgraded golang to Go compiler version 1.26.3 in the postgres sidecar | Multiple | Critical |
| github.com/golang/go9 | Upgraded golang-go in the opamp-svc binary to version 1.25.11 | Multiple | Critical |
| github.com/go-jose/go-jose/v410 | Upgraded go-jose in the opamp-svc binary to version 4.1.4 | CVE-2026-34986 | High |
| go.opentelemetry.io/otel11 | Upgraded opentelemetry/otel in opamp-svc to version 1.43.0 | CVE-2026-29181 | High |
| go.opentelemetry.io/otel/sdk12 | Upgraded opentelemetry/otel/sdk in opamp-svc to version 1.43.0 | CVE-2026-39883 | High |
| google.golang.org/grpc13 | Upgraded golang-grpc in opamp-svc to version 1.80.0 | CVE-2026-33186 | Critical |
| libcurl14 | Upgraded libcurl to version 8.20.0 | Multiple | Medium |
| idna15 | Upgraded idna to version 3.18 | CVE-2026-45409 | Medium |
| PostgreSQL16 | Upgraded PostgreSQL to version 17.10 | Multiple | High |
| OpenSSL17 | Upgraded OpenSSL to versions 1.0.2zq and 3.5.7 | Multiple | High |
| MongoDB18 | Upgraded MongoDB 7.0.34 to version 7.0.37 and MongoDB 8.0.23 to version 8.0.26 | CVE-2024-35255 | Medium |
1 Upgraded golang to Go 1.26.3 to remedy CVE-2026-25679, CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, and CVE-2026-33810 at /opt/packages/ipc_broker-v1.9.5-36253eb8-20260309t135542.tar.gz/ipc_broker.
2 Upgraded go-jose in the ipc-broker binary to version 4.1.4 to remedy CVE-2026-34986 at /opt/packages/ipc_broker-v1.9.5-36253eb8-20260309t135542.tar.gz/ipc_broker.
3 Upgraded opentelemetry/otel in the ipc-broker binary to version 1.44.0 to remedy CVE-2026-29181 at /opt/packages/ipc_broker-v1.9.5-36253eb8-20260309t135542.tar.gz/ipc_broker.
4 Upgraded opentelemetry/otel/sdk in the ipc-broker binary to version 1.44.0 to remedy CVE-2026-39883 at /opt/packages/ipc_broker-v1.9.5-36253eb8-20260309t135542.tar.gz/ipc_broker.
5 Upgraded go-jose in the splunk-topology sidecar to version 4.1.4 to remedy CVE-2026-34986 at /opt/splunk/var/run/supervisor/pkg-run/pkg-topology1037764223/splunk-topology.
6 Upgraded opentelemetry/otel in the splunk-topology sidecar to version 1.44.0 to remedy CVE-2026-29181 at /opt/splunk/var/run/supervisor/pkg-run/pkg-topology1037764223/splunk-topology.
7 Upgraded opentelemetry/otel/sdk in the splunk-topology sidecar to version 1.44.0 to remedy CVE-2026-39883 at /opt/splunk/var/run/supervisor/pkg-run/pkg-topology1037764223/splunk-topology.
8 Upgraded golang to Go 1.26.3 in the postgres sidecar to remedy CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, and CVE-2026-32283 at /opt/splunk/bin/postgres.
9 Upgraded golang-go in the opamp-svc binary to version 1.25.11 to remedy CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, and CVE-2026-32283 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.
10 Upgraded go-jose in the opamp-svc binary to version 4.1.4 to remedy CVE-2026-34986 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.
11 Upgraded opentelemetry/otel in the opamp-svc binary to version 1.43.0 to remedy CVE-2026-29181 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.
12 Upgraded opentelemetry/otel/sdk in the opamp-svc binary to version 1.43.0 to remedy CVE-2026-39883 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.
13 Upgraded golang-grpc in the opamp-svc binary to version 1.80.0 to remedy CVE-2026-33186 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.
14 Upgraded libcurl to version 8.20.0 to remedy CVE-2026-7168, CVE-2026-6429, CVE-2026-6276, CVE-2025-14819, and CVE-2025-14017 at /opt/splunk/opt/mongo/lib/libcurl.so.4.8.0 in Splunk Enterprise version 10.4.2.
15 Upgraded idna to version 3.18 to remedy CVE-2026-45409 at /opt/splunk/etc/apps/splunk_secure_gateway/lib/idna-3.18.dist-info/METADATA.
16 Upgraded PostgreSQL to version 17.10 to remedy CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6638, and CVE-2026-6637 at /opt/splunk/bin/postgres in Splunk Enterprise versions 10.4.2, 10.2.6, and 10.0.9. Splunk Enterprise versions 9.x do not include PostgreSQL.
17 For Splunk Enterprise version 10.4.x, Splunk Enterprise upgraded OpenSSL 1.0.2zp to version 1.0.2zq at /opt/splunk/opt/openssl1/bin/openssl, /opt/splunk/lib/libssl.so.1.0.0, and /opt/splunk/lib/libcrypto.so.1.0.0, and upgraded OpenSSL 3.5.6 to version 3.5.7 at /opt/splunk/lib/libssl.so.3, /opt/splunk/lib/libcrypto.so.3, /opt/splunk/lib/libssl.so, and /opt/splunk/lib/libcrypto.so to remedy CVE-2026-45447, CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, and CVE-2026-42766. For Splunk Enterprise versions 10.2.x, 10.1.x, and 10.0.x, Splunk Enterprise upgraded OpenSSL 1.0.2zp to version 1.0.2zq at /opt/splunk/opt/openssl1/bin/openssl, /opt/splunk/lib/libssl.so.1.0.0, and /opt/splunk/lib/libcrypto.so.1.0.0, and upgraded OpenSSL 3.0.20 to version 3.0.21 at /opt/splunk/lib/libssl.so.3, /opt/splunk/lib/libcrypto.so.3, /opt/splunk/lib/libssl.so, and /opt/splunk/lib/libcrypto.so to remedy CVE-2026-45447, CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, and CVE-2026-42766. For Splunk Enterprise versions 9.4.x and 9.3.x, Splunk Enterprise upgraded OpenSSL 1.0.2zp to version 1.0.2zq at /opt/splunk/opt/openssl1/bin/openssl, /opt/splunk/lib/libssl.so.1.0.0, and /opt/splunk/lib/libcrypto.so.1.0.0 to remedy CVE-2026-45447, CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, and CVE-2026-42766.
18 For Splunk Enterprise versions 9.4.14 and 10.0.9 for Linux and Windows, Splunk Enterprise upgraded MongoDB 7.0 from version 7.0.34 to version 7.0.37 at $SPLUNK_HOME/bin/mongod to remediate CVE-2024-35255. For Splunk Enterprise version 10.2.6 for Linux, Windows, and macOS, Splunk Enterprise upgraded MongoDB 8.0 from version 8.0.23 to version 8.0.26 and MongoDB 7.0 from version 7.0.34 to version 7.0.37 at $SPLUNK_HOME/bin/mongod to remediate CVE-2024-35255. For Splunk Enterprise version 10.4.2 for Linux, Windows, and macOS, Splunk Enterprise upgraded MongoDB 7.0 from version 7.0.34 to version 7.0.37 and MongoDB 8.0 from version 8.0.23 to version 8.0.26 at $SPLUNK_HOME/bin/mongod to remediate CVE-2024-35255.
Solution
Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, 9.4.14, or higher.
Product Status
| Product | Base Version | Affected Version | Fix Version |
|---|---|---|---|
| Splunk Enterprise | 10.4 | 10.4.0 to 10.4.1 | 10.4.2 |
| Splunk Enterprise | 10.2 | 10.2.0 to 10.2.5 | 10.2.6 |
| Splunk Enterprise | 10.0 | 10.0.0 to 10.0.8 | 10.0.9 |
| Splunk Enterprise | 9.4 | 9.4.0 to 9.4.13 | 9.4.14 |
Severity
For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.