CVE-2026-20298 – Splunk Enterprise and Splunk Cloud Platform

CVSS 5.3 MODERATE High with EoP or RCE – Expedited Deployment

“These weaknesses put stored credentials, indexed data, and application files within reach of attackers.”

Splunk patched three vulnerabilities affecting Splunk Enterprise and Splunk Cloud Platform. CVE-2026-20296 can let an attacker trick an authorized user into running SPL searches as splunk-system-user, exposing stored credentials and indexed data. CVE-2026-20296 has a CVSS score of 8.3, which is High severity.

CVE-2026-20297 allows a privileged user to write files outside the intended application directory during app installation. CVE-2026-20297 has a CVSS score of 7.2, which is High severity. CVE-2026-20298 allows a low-privileged user to view stored credential hashes through a REST endpoint. CVE-2026-20298 has a CVSS score of 5.3, which is Medium severity. Updated Splunk releases correct these weaknesses.

Key Details

Affected Product
Splunk Splunk
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-200
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.