CVE-2023-40593: Splunk

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.

Affected products

  • Splunk Splunk: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6)
  • Splunk Splunk Cloud Platform: up to and including 9.0.2305.100

Published 2023-08-30. Last modified 2026-06-17.