CVE-2026-20296 – Splunk Enterprise and Splunk Cloud Platform
“These weaknesses put stored credentials, indexed data, and application files within reach of attackers.”
Splunk patched three vulnerabilities affecting Splunk Enterprise and Splunk Cloud Platform. CVE-2026-20296 can let an attacker trick an authorized user into running SPL searches as splunk-system-user, exposing stored credentials and indexed data. CVE-2026-20296 has a CVSS score of 8.3, which is High severity.
CVE-2026-20297 allows a privileged user to write files outside the intended application directory during app installation. CVE-2026-20297 has a CVSS score of 7.2, which is High severity. CVE-2026-20298 allows a low-privileged user to view stored credential hashes through a REST endpoint. CVE-2026-20298 has a CVSS score of 5.3, which is Medium severity. Updated Splunk releases correct these weaknesses.
Key Details
- Affected Product
- Splunk Splunk
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-352