CVE-2023-46231: Splunk Add-On Builder

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.

Affected products

  • Splunk Add-On Builder: before 4.1.4 (fixed in 4.1.4)

Published 2024-01-30. Last modified 2026-06-17.