CVE-2022-32156 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configure TLS host name validation for the Splunk CLI [here](https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_TLS_host_name_validation_for_the_Splunk_CLI) to enable the remediation. EPSS estimates a 0.74% chance of exploitation in the next 30 days.

## Description

In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. This vulnerability does not affect the Splunk Cloud Platform. The issue requires conditions beyond the control of a potential bad actor, such as a machine-in-the-middle attack. Hence, Splunk rates the complexity of the attack as High.

## Metrics

- **CVSS**: 8.1/10
- **CVSS vector**: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- **EPSS Probability**: 0.74% (50.0th percentile)
- Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-295](https://cwe.mitre.org/data/definitions/295.html)
- [CWE-295](https://cwe.mitre.org/data/definitions/295.html)

## Affected Software

| Vendor | Product | Versions |
| --- | --- | --- |
| Splunk | Splunk | < 9.0 |
| Splunk | Universal Forwarder | < 9.0 |

## References

- [Mitigation, Vendor Advisory](https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_TLS_host_name_validation_for_the_Splunk_CLI)
- [Release Notes, Vendor Advisory](https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/Updates)
- [Vendor Advisory](https://www.splunk.com/en_us/product-security/announcements/svd-2022-0606.html)

## Timeline

- **Published**: Jun 15, 2022
- **Last Modified**: Jun 17, 2026
- **Status**: Modified

## Frequently Asked Questions

### What is CVE-2022-32156?
In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default.

### How severe is CVE-2022-32156?
CVE-2022-32156 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.74% probability of exploitation in the next 30 days.

### How do I fix CVE-2022-32156?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.

### Are you affected by CVE-2022-32156?
Run a free Strix scan to check your systems for this vulnerability. [Scan your code now](https://app.strix.ai/)

[Source: NVD / NIST](https://nvd.nist.gov/vuln/detail/CVE-2022-32156)
