CVE-2016-10126
Last modified
CVE-2016-10126 is a vulnerability of currently unknown severity. Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.. EPSS estimates a 3.99% chance of exploitation in the next 30 days.
Description
Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | 5.0.0 |
| Splunk | Splunk | 5.0.1 |
| Splunk | Splunk | 5.0.2 |
| Splunk | Splunk | 5.0.3 |
| Splunk | Splunk | 5.0.4 |
| Splunk | Splunk | 5.0.5 |
| Splunk | Splunk | 5.0.6 |
| Splunk | Splunk | 5.0.7 |
| Splunk | Splunk | 5.0.8 |
| Splunk | Splunk | 5.0.9 |
| Splunk | Splunk | 5.0.10 |
| Splunk | Splunk | 5.0.11 |
| Splunk | Splunk | 5.0.12 |
| Splunk | Splunk | 5.0.13 |
| Splunk | Splunk | 5.0.14 |
| Splunk | Splunk | 5.0.15 |
| Splunk | Splunk | 5.0.16 |
| Splunk | Splunk | 6.0.0 |
| Splunk | Splunk | 6.0.1 |
| Splunk | Splunk | 6.0.2 |
| Splunk | Splunk | 6.0.3 |
| Splunk | Splunk | 6.0.4 |
| Splunk | Splunk | 6.0.5 |
| Splunk | Splunk | 6.0.6 |
| Splunk | Splunk | 6.0.7 |
| Splunk | Splunk | 6.0.8 |
| Splunk | Splunk | 6.0.9 |
| Splunk | Splunk | 6.0.10 |
| Splunk | Splunk | 6.0.11 |
| Splunk | Splunk | 6.0.12 |
| Splunk | Splunk | 6.1.0 |
| Splunk | Splunk | 6.1.1 |
| Splunk | Splunk | 6.1.2 |
| Splunk | Splunk | 6.1.3 |
| Splunk | Splunk | 6.1.4 |
| Splunk | Splunk | 6.1.5 |
| Splunk | Splunk | 6.1.6 |
| Splunk | Splunk | 6.1.7 |
| Splunk | Splunk | 6.1.8 |
| Splunk | Splunk | 6.1.9 |
| Splunk | Splunk | 6.1.10 |
| Splunk | Splunk | 6.1.11 |
| Splunk | Splunk | 6.2.0 |
| Splunk | Splunk | 6.2.1 |
| Splunk | Splunk | 6.2.2 |
| Splunk | Splunk | 6.2.3 |
| Splunk | Splunk | 6.2.4 |
| Splunk | Splunk | 6.2.5 |
| Splunk | Splunk | 6.2.6 |
| Splunk | Splunk | 6.2.7 |
Showing 50 of 66 affected configurations. See NVD for the full list.
References
- https://www.splunk.com/view/SP-CAAAPSRMitigation, Vendor Advisory
- https://www.splunk.com/view/SP-CAAAPSRMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10126?
How severe is CVE-2016-10126?
How do I fix CVE-2016-10126?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10120Firejail uses 0777 permissions when mounting (1) /dev, (2) /…
- CVE-2016-10121Firejail uses weak permissions for /dev/shm/firejail and pos…
- CVE-2016-10122Firejail does not properly clean environment variables, whic…
- CVE-2016-10123Firejail allows --chroot when seccomp is not supported, whic…
- CVE-2016-10124An issue was discovered in Linux Containers (LXC) before 201…
- CVE-2016-10125D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a …
- CVE-2016-10127PySAML2 allows remote attackers to conduct XML external enti…
- CVE-2016-10128Buffer overflow in the git_pkt_parse_line function in transp…
- CVE-2016-10129The Git Smart Protocol support in libgit2 before 0.24.6 and …
- CVE-2016-1013Use-after-free vulnerability in Adobe Flash Player before 18…8.8
- CVE-2016-10130The http_connect function in transports/http.c in libgit2 be…
- CVE-2016-10131system/libraries/Email.php in CodeIgniter before 3.1.3 allow…
Are you affected by CVE-2016-10126?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
