SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-20296

HIGH · CVSS 8.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

In Splunk Enterprise and Splunk Cloud Platform versions prior to specified updates, a vulnerability allows attackers to exploit users with the `list_deployment_server` capability, executing arbitrary Search Processing Language (SPL) searches as the `splunk-system-user`. This could lead to unauthorized access to sensitive stored credentials and indexed data due to inadequate CSRF token validation and improper input handling. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure and potential system compromise.

CVE
CVE-2026-20296
Severity
HIGH
CVSS
8.3
EPSS
0.23%

Original NVD Description

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing Language (SPL) searches on their behalf as `splunk-system-user`, allowing for access to stored credentials and indexed data.<br><br>The vulnerability is possible because Deployment Server endpoints in Splunk Web do not validate Cross-Site Request Forgery (CSRF) tokens on GET requests, and caller-supplied input is not correctly neutralized before it is placed into an SPL search.

Related CVEs

Other vulnerabilities affecting the same vendor(s)