CVE-2024-36982: Splunk Cloud

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.

Affected products

  • Splunk Cloud: from 9.1.2308, before 9.1.2308.207 (fixed in 9.1.2308.207); from 9.1.2312.100, before 9.1.2312.109 (fixed in 9.1.2312.109)
  • Splunk Splunk: from 9.0.0, before 9.0.10 (fixed in 9.0.10); from 9.1.0, before 9.1.5 (fixed in 9.1.5); from 9.2.0, before 9.2.2 (fixed in 9.2.2)

Published 2024-07-01. Last modified 2026-06-17.