Splunk Patches Critical Vulnerabilities Exposing Data, Enabling DoS Attacks
Key Takeaways Splunk has released urgent security updates for Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit. The patches address three critical vulnerabilities (CVE-2026-20238,...
Key Takeaways
- Splunk has released urgent security updates for Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit.
- The patches address three critical vulnerabilities (CVE-2026-20238, CVE-2026-20239, CVE-2026-20240) that could lead to sensitive data exposure and denial-of-service (DoS) attacks.
- Affected versions span multiple product lines, with CVSS scores ranging from 6.5 to 7.5, indicating medium to high severity.
- Users are strongly advised to upgrade immediately or implement specified mitigations to protect against exploitation.
Splunk Addresses Critical Vulnerabilities Across Enterprise and Cloud Platforms
Splunk has rolled out crucial security updates for its core products, including Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit. These patches target a series of vulnerabilities that could enable attackers to gain unauthorized access to sensitive data or disrupt service availability through denial-of-service attacks.
Table Of Content
The issues, publicly disclosed on May 20, 2026, encompass three distinct vulnerabilities identified as CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240.
Splunk AI Toolkit Access Flaw (CVE-2026-20238)
A medium-severity vulnerability, CVE-2026-20238 (CVSS 6.5), has been identified within Splunk AI Toolkit versions prior to 5.7.3. This flaw originates from misconfigured role inheritance, leading to improper access controls.
The vulnerability arises because the AI Toolkit modifies the default ‘user’ role via an authorize.conf file containing a srchFilter entry. Due to Splunk’s use of the OR operator when combining inherited search filters, this configuration can inadvertently override more stringent filters applied to custom roles.
Consequently, users with lower privileges, who do not possess ‘admin’ or ‘power’ roles, might gain access to sensitive data that should otherwise be restricted. Splunk has rectified this issue in version 5.7.3.
As a temporary measure, organizations can disable the AI Toolkit or manually adjust the authorization.conf file to remove or supersede the srchFilter setting. However, implementing this workaround may expose the ai_agent_run_history_index to broader access, necessitating further access restrictions.
Sensitive Data Exposure via Logs (CVE-2026-20239)
A high-severity vulnerability, CVE-2026-20239 (CVSS 7.5), impacts both Splunk Enterprise and Splunk Cloud Platform. This flaw resides in the TcpChannel component, where improper output sanitization allows the logging of entire input/output buffers when socket errors occur.
Attackers who manage to gain access to the _internal index can extract sensitive information, such as session cookies and HTTP response bodies, directly from these log files. This significantly elevates the risk of credential theft and session hijacking.
Affected versions include:
- Splunk Enterprise versions earlier than 10.2.2 and 10.0.5.
- Splunk Cloud Platform versions preceding multiple patched releases across supported branches.
Splunk advises immediate upgrades to the latest patched versions and emphasizes the importance of restricting access to the _internal index exclusively to administrative roles.
Denial-of-Service in Splunk Archiver (CVE-2026-20240)
Another high-severity issue, CVE-2026-20240 (CVSS 7.1), affects the Splunk Archiver app. This vulnerability stems from improper input validation within the coldToFrozen.sh script, which is responsible for managing data lifecycle transitions.
A low-privileged user could exploit this flaw by providing arbitrary file paths, enabling them to rename critical directories. Such an action can render the Splunk instance inoperable, leading to a denial-of-service condition.
This vulnerability affects multiple versions of Splunk Enterprise (specifically, versions prior to 10.2.2, 10.0.5, 9.4.11, and 9.3.12) and various Splunk Cloud Platform deployments.
Organizations are urged to apply the necessary patches without delay. Alternatively, if the Splunk Archiver app is not essential, it can be disabled, though this might disrupt automated data archiving workflows.
What You Should Do
- Upgrade Immediately: Update all affected Splunk components (Splunk Enterprise, Splunk Cloud Platform, Splunk AI Toolkit, and Splunk Archiver app) to the latest secure versions as recommended by Splunk.
- Restrict Access: Limit access to sensitive indexes, particularly the
_internalindex, to administrative roles only. - Review Role-Based Controls: Conduct a thorough review of existing role-based access controls and inherited permissions to ensure they align with the principle of least privilege.
- Disable Non-Essential Apps: If immediate patching is not feasible, disable vulnerable applications, such as the Splunk Archiver app, if they are not critical to operations. Be aware of potential workflow interruptions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.