Third-Party Package Updates in Splunk Enterprise - September/October 2026
Advisory ID: SVD-2026-1003
CVE ID:
Published: 2026-10-07
Last Update: 2026-10-07
Description
Splunk remedied common vulnerabilities and exposures (CVEs) in third-party packages in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 or higher.
| Package | Remediation | CVE | Severity |
|---|---|---|---|
| golang.org/x/crypto1 | Upgraded golang.org/x/crypto in the etcd binary to version 0.52.0 | Multiple | Critical |
| golang.org/x/net2 | Upgraded golang.org/x/net in the etcd binary to version 0.55.0 | CVE-2026-39821 | Critical |
| golang.org/x/crypto3 | Upgraded golang.org/x/crypto in the etcdutl binary to version 0.52.0 | Multiple | Critical |
| golang.org/x/net4 | Upgraded golang.org/x/net in the etcdutl binary to version 0.55.0 | CVE-2026-39821 | Critical |
| golang.org/x/net5 | Upgraded golang.org/x/net in the spl2-preview binary to version 0.56.0 | Multiple | Critical |
| golang.org/x/crypto6 | Upgraded golang.org/x/crypto in the spl2-preview binary to version 0.53.0 | Multiple | Critical |
| golang.org/x/crypto7 | Upgraded golang.org/x/crypto in the compsup binary to version 0.53.0 | Multiple | Critical |
| golang.org/x/net8 | Upgraded golang.org/x/net in the compsup binary to version 0.56.0 | Multiple | Critical |
| github.com/golang/go9 | Upgraded the Go compiler used to build the etcd binary to version 1.25.11 | Multiple | High |
| github.com/golang/go10 | Upgraded the Go compiler used to build the etcd binary to version 1.26.4 | Multiple | High |
| github.com/go-jose/go-jose/v411 | Upgraded github.com/go-jose/go-jose/v4 in agent-manager to version 4.1.4 | CVE-2026-34986 | High |
| golang.org/x/crypto12 | Upgraded golang.org/x/crypto in agent-manager to version 0.53.0 | Multiple | Critical |
| golang.org/x/net13 | Upgraded golang.org/x/net in agent-manager to version 0.56.0 | Multiple | Critical |
| libcurl14 | Upgraded libcurl to version 8.21.0 | Multiple | Medium |
| go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp15 | Upgraded go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to version 1.43.0 | CVE-2026-39882 | Medium |
1 Upgraded golang.org/x/crypto in the etcd binary to version 0.52.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, CVE-2026-46595 at $SPLUNK_HOME/bin/etcd.
2 Upgraded golang.org/x/net in the etcd binary to version 0.55.0 to remedy CVE-2026-39821 at $SPLUNK_HOME/bin/etcd.
3 Upgraded golang.org/x/crypto in the etcdutl binary to version 0.52.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, CVE-2026-46595 at $SPLUNK_HOME/bin/etcdutl.
4 Upgraded golang.org/x/net in the etcdutl binary to version 0.55.0 to remedy CVE-2026-39821 at $SPLUNK_HOME/bin/etcdutl.
5 Upgraded golang.org/x/net in the spl2-preview binary to version 0.56.0 to remedy CVE-2026-27141 and CVE-2026-39821 at $SPLUNK_HOME/bin/spl2-orchestrator in Splunk Enterprise version 10.4.3. The spl2-preview binary is not present in Splunk Enterprise versions 10.2.x, 10.0.x and 9.4.x.
6 Upgraded golang.org/x/crypto in the spl2-preview binary to version 0.53.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, and CVE-2026-46595 at $SPLUNK_HOME/bin/spl2-orchestrator in Splunk Enterprise version 10.4.3. The spl2-preview binary is not present in Splunk Enterprise versions 10.2.x, 10.0.x and 9.4.x.
7 Upgraded golang.org/x/crypto in the compsup binary to version 0.53.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, CVE-2026-46595 at $SPLUNK_HOME/bin/compsup.
8 Upgraded golang.org/x/net in the compsup binary to version 0.56.0 to remedy CVE-2026-27141 and CVE-2026-39821 at $SPLUNK_HOME/bin/compsup.
9 Upgraded the Go compiler used to build the etcd binary to version 1.25.11 to remedy CVE-2026-33811, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, and CVE-2026-42499 at $SPLUNK_HOME/bin/etcd in Splunk Enterprise version 10.2.7.
10 Upgraded the Go compiler used to build the etcd binary to version 1.26.4 to remedy CVE-2026-33811, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, and CVE-2026-42499 at $SPLUNK_HOME/bin/etcd in Splunk Enterprise version 10.4.3.
11 Upgraded github.com/go-jose/go-jose/v4 in agent-manager to version 4.1.4 to remedy CVE-2026-34986 at $SPLUNK_HOME/var/run/supervisor/pkg-run/pkg-agent-manager1023957353/agent-manager.
12 Upgraded golang.org/x/crypto in agent-manager to version 0.53.0 to remedy CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508 and CVE-2026-46595 at $SPLUNK_HOME/var/run/supervisor/pkg-run/pkg-agent-manager1023957353/agent-manager.
13 Upgraded golang.org/x/net in agent-manager to version 0.56.0 to remedy CVE-2026-27141 and CVE-2026-39821 at $SPLUNK_HOME/var/run/supervisor/pkg-run/pkg-agent-manager1023957353/agent-manager.
14 Upgraded libcurl to version 8.21.0 to remedy CVE-2026-9079, CVE-2026-8927, CVE-2026-8286, CVE-2026-8926, CVE-2026-8924 and CVE-2026-9545 at $SPLUNK_HOME/mongo/lib/libcurl.so.4.8.0 in Splunk Enterprise version 10.4.3.
15 Upgraded go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to version 1.43.0 to remedy CVE-2026-39882 at $SPLUNK_HOME/var/run/supervisor/pkg-run/pkg-postgres690279569/splunk-postgres.
Solution
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 or higher.
Product Status
| Product | Base Version | Affected Version | Fix Version |
|---|---|---|---|
| Splunk Enterprise | 10.4 | 10.4.0 to 10.4.2 | 10.4.3 |
| Splunk Enterprise | 10.2 | 10.2.0 to 10.2.6 | 10.2.7 |
| Splunk Enterprise | 10.0 | 10.0.0 to 10.0.9 | 10.0.10 |
| Splunk Enterprise | 9.4 | 9.4.0 to 9.4.14 | 9.4.15 |
Severity
Unless otherwise stated, Splunk adopts the vendor’s severity rating first, if available, or the National Vulnerability Database (NVD)’s rating, otherwise.