Third-Party Package Updates in Splunk Enterprise - September/October 2026

Advisory ID: SVD-2026-1003

CVE ID: 

Published: 2026-10-07

Last Update: 2026-10-07

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in third-party packages in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 or higher.

PackageRemediationCVESeverity
golang.org/x/crypto1Upgraded golang.org/x/crypto in the etcd binary to version 0.52.0MultipleCritical
golang.org/x/net2Upgraded golang.org/x/net in the etcd binary to version 0.55.0CVE-2026-39821Critical
golang.org/x/crypto3Upgraded golang.org/x/crypto in the etcdutl binary to version 0.52.0MultipleCritical
golang.org/x/net4Upgraded golang.org/x/net in the etcdutl binary to version 0.55.0CVE-2026-39821Critical
golang.org/x/net5Upgraded golang.org/x/net in the spl2-preview binary to version 0.56.0MultipleCritical
golang.org/x/crypto6Upgraded golang.org/x/crypto in the spl2-preview binary to version 0.53.0MultipleCritical
golang.org/x/crypto7Upgraded golang.org/x/crypto in the compsup binary to version 0.53.0MultipleCritical
golang.org/x/net8Upgraded golang.org/x/net in the compsup binary to version 0.56.0MultipleCritical
github.com/golang/go9Upgraded the Go compiler used to build the etcd binary to version 1.25.11MultipleHigh
github.com/golang/go10Upgraded the Go compiler used to build the etcd binary to version 1.26.4MultipleHigh
github.com/go-jose/go-jose/v411Upgraded github.com/go-jose/go-jose/v4 in agent-manager to version 4.1.4CVE-2026-34986High
golang.org/x/crypto12Upgraded golang.org/x/crypto in agent-manager to version 0.53.0MultipleCritical
golang.org/x/net13Upgraded golang.org/x/net in agent-manager to version 0.56.0MultipleCritical
libcurl14Upgraded libcurl to version 8.21.0MultipleMedium
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp15Upgraded go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to version 1.43.0CVE-2026-39882Medium

1 Upgraded golang.org/x/crypto in the etcd binary to version 0.52.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, CVE-2026-46595 at $SPLUNK_HOME/bin/etcd.

2 Upgraded golang.org/x/net in the etcd binary to version 0.55.0 to remedy CVE-2026-39821 at $SPLUNK_HOME/bin/etcd.

3 Upgraded golang.org/x/crypto in the etcdutl binary to version 0.52.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, CVE-2026-46595 at $SPLUNK_HOME/bin/etcdutl.

4 Upgraded golang.org/x/net in the etcdutl binary to version 0.55.0 to remedy CVE-2026-39821 at $SPLUNK_HOME/bin/etcdutl.

5 Upgraded golang.org/x/net in the spl2-preview binary to version 0.56.0 to remedy CVE-2026-27141 and CVE-2026-39821 at $SPLUNK_HOME/bin/spl2-orchestrator in Splunk Enterprise version 10.4.3. The spl2-preview binary is not present in Splunk Enterprise versions 10.2.x, 10.0.x and 9.4.x.

6 Upgraded golang.org/x/crypto in the spl2-preview binary to version 0.53.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, and CVE-2026-46595 at $SPLUNK_HOME/bin/spl2-orchestrator in Splunk Enterprise version 10.4.3. The spl2-preview binary is not present in Splunk Enterprise versions 10.2.x, 10.0.x and 9.4.x.

7 Upgraded golang.org/x/crypto in the compsup binary to version 0.53.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, CVE-2026-46595 at $SPLUNK_HOME/bin/compsup.

8 Upgraded golang.org/x/net in the compsup binary to version 0.56.0 to remedy CVE-2026-27141 and CVE-2026-39821 at $SPLUNK_HOME/bin/compsup.

9 Upgraded the Go compiler used to build the etcd binary to version 1.25.11 to remedy CVE-2026-33811, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, and CVE-2026-42499 at $SPLUNK_HOME/bin/etcd in Splunk Enterprise version 10.2.7.

10 Upgraded the Go compiler used to build the etcd binary to version 1.26.4 to remedy CVE-2026-33811, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, and CVE-2026-42499 at $SPLUNK_HOME/bin/etcd in Splunk Enterprise version 10.4.3.

11 Upgraded github.com/go-jose/go-jose/v4 in agent-manager to version 4.1.4 to remedy CVE-2026-34986 at $SPLUNK_HOME/var/run/supervisor/pkg-run/pkg-agent-manager1023957353/agent-manager.

12 Upgraded golang.org/x/crypto in agent-manager to version 0.53.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508 and CVE-2026-46595 at $SPLUNK_HOME/var/run/supervisor/pkg-run/pkg-agent-manager1023957353/agent-manager.

13 Upgraded golang.org/x/net in agent-manager to version 0.56.0 to remedy CVE-2026-27141 and CVE-2026-39821 at $SPLUNK_HOME/var/run/supervisor/pkg-run/pkg-agent-manager1023957353/agent-manager.

14 Upgraded libcurl to version 8.21.0 to remedy CVE-2026-9079, CVE-2026-8927, CVE-2026-8286, CVE-2026-8926, CVE-2026-8924 and CVE-2026-9545 at $SPLUNK_HOME/mongo/lib/libcurl.so.4.8.0 in Splunk Enterprise version 10.4.3.

15 Upgraded go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to version 1.43.0 to remedy CVE-2026-39882 at $SPLUNK_HOME/var/run/supervisor/pkg-run/pkg-postgres690279569/splunk-postgres.

Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk Enterprise10.410.4.0 to 10.4.210.4.3
Splunk Enterprise10.210.2.0 to 10.2.610.2.7
Splunk Enterprise10.010.0.0 to 10.0.910.0.10
Splunk Enterprise9.49.4.0 to 9.4.149.4.15

Severity

Unless otherwise stated, Splunk adopts the vendor’s severity rating first, if available, or the National Vulnerability Database (NVD)’s rating, otherwise.