CVE-2026-20296 – Splunk Enterprise and Splunk Cloud Platform

CVSS 8.3 IMPORTANT High with EoP or RCE – Expedited Deployment

“These weaknesses put stored credentials, indexed data, and application files within reach of attackers.”

Splunk patched three vulnerabilities affecting Splunk Enterprise and Splunk Cloud Platform. CVE-2026-20296 can let an attacker trick an authorized user into running SPL searches as splunk-system-user, exposing stored credentials and indexed data. CVE-2026-20296 has a CVSS score of 8.3, which is High severity.

CVE-2026-20297 allows a privileged user to write files outside the intended application directory during app installation. CVE-2026-20297 has a CVSS score of 7.2, which is High severity. CVE-2026-20298 allows a low-privileged user to view stored credential hashes through a REST endpoint. CVE-2026-20298 has a CVSS score of 5.3, which is Medium severity. Updated Splunk releases correct these weaknesses.

Key Details

Affected Product
Splunk Splunk
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-352
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.