CVE-2023-40596: Splunk
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.
Affected products
- Splunk Splunk: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only
Published 2023-08-30. Last modified 2026-06-17.