CVE-2026-7589
Last modified
CVE-2026-7589 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Impacted is the function create_csv_export of the file services/csv-export-service/app/api/v1/endpoints/csv_export.py of the component CSV Export. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Impacted is the function create_csv_export of the file services/csv-export-service/app/api/v1/endpoints/csv_export.py of the component CSV Export. This manipulation of the argument job_name causes path traversal. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7589?
How severe is CVE-2026-7589?
How do I fix CVE-2026-7589?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75883The code in pppd that formats a response to a PEAP Request p…6.8
- CVE-2026-75884A flaw was found in AWX. The container group pod_spec_overri…9.1
- CVE-2026-75885A flaw was found in the OpenShift console. Unauthenticated a…9.3
- CVE-2026-75886A flaw was found in openshift/console. An unauthenticated re…7.2
- CVE-2026-75887A flaw was found in the OpenShift console. An unauthenticate…7.5
- CVE-2026-75889Grafana Alloy’s prometheus.operator.servicemonitors componen…7.7
- CVE-2026-75890Rejected reason: Duplicate of CVE-2026-50236. This CVE ID wa…
- CVE-2026-75892In osmo-ggsn 1.14.0 an out of bounds write issue was found i…6.5
- CVE-2026-75893In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer ov…7.5
- CVE-2026-75894In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion w…7.5
- CVE-2026-75895In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issu…7.5
- CVE-2026-75896Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGE…9.1
Are you affected by CVE-2026-7589?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
