CVE-2017-17067: Splunk

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intended access restrictions or conduct impersonation attacks.

Affected products

  • Splunk Splunk: from 6.3.0, before 6.3.12 (fixed in 6.3.12); from 6.4.0, before 6.4.9 (fixed in 6.4.9); from 6.5.0, before 6.5.6 (fixed in 6.5.6); from 6.6.0, before 6.6.3.2 (fixed in 6.6.3.2); from 7.0.0, before 7.0.0.1 (fixed in 7.0.0.1)

Published 2017-11-30. Last modified 2026-06-17.