CVE-2022-26070
Last modified
CVE-2022-26070 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | < 8.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-26070?
How severe is CVE-2022-26070?
How do I fix CVE-2022-26070?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-26062Uncontrolled search path element in the Intel(R) Trace Analy…7.3
- CVE-2022-26065Delta Electronics DIAEnergie (All versions prior to 1.8.02.0…9.8
- CVE-2022-26067An information disclosure vulnerability exists in the OAS En…7.5
- CVE-2022-26068This affects the package pistacheio/pistache before 0.0.3.20…7.5
- CVE-2022-26069Delta Electronics DIAEnergie (All versions prior to 1.8.02.0…9.8
- CVE-2022-2607Use after free in Tab Strip in Google Chrome on Chrome OS pr…8.8
- CVE-2022-26071On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versi…7.5
- CVE-2022-26072Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-26073A denial of service vulnerability exists in the libxm_av.so …6.5
- CVE-2022-26074Incomplete cleanup in a firmware subsystem for Intel(R) SPS …4.4
- CVE-2022-26075An OS command injection vulnerability exists in the console …8.8
- CVE-2022-26076Uncontrolled search path element in the Intel(R) oneAPI Deep…7.3
Are you affected by CVE-2022-26070?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
