Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Home/CyberSecurity News/Splunk Patches Critical Vulnerabilities Exposing Data, Enabling DoS Attacks
CyberSecurity News

Splunk Patches Critical Vulnerabilities Exposing Data, Enabling DoS Attacks

Key Takeaways Splunk has released urgent security updates for Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit. The patches address three critical vulnerabilities (CVE-2026-20238,...

Marcus Rodriguez
Marcus Rodriguez
May 22, 2026 3 Min Read
57 0

Key Takeaways

  • Splunk has released urgent security updates for Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit.
  • The patches address three critical vulnerabilities (CVE-2026-20238, CVE-2026-20239, CVE-2026-20240) that could lead to sensitive data exposure and denial-of-service (DoS) attacks.
  • Affected versions span multiple product lines, with CVSS scores ranging from 6.5 to 7.5, indicating medium to high severity.
  • Users are strongly advised to upgrade immediately or implement specified mitigations to protect against exploitation.

Splunk Addresses Critical Vulnerabilities Across Enterprise and Cloud Platforms

Splunk has rolled out crucial security updates for its core products, including Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit. These patches target a series of vulnerabilities that could enable attackers to gain unauthorized access to sensitive data or disrupt service availability through denial-of-service attacks.

Table Of Content

  • Key Takeaways
  • Splunk Addresses Critical Vulnerabilities Across Enterprise and Cloud Platforms
  • Splunk AI Toolkit Access Flaw (CVE-2026-20238)
  • Sensitive Data Exposure via Logs (CVE-2026-20239)
  • Denial-of-Service in Splunk Archiver (CVE-2026-20240)
  • What You Should Do

The issues, publicly disclosed on May 20, 2026, encompass three distinct vulnerabilities identified as CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240.

Splunk AI Toolkit Access Flaw (CVE-2026-20238)

A medium-severity vulnerability, CVE-2026-20238 (CVSS 6.5), has been identified within Splunk AI Toolkit versions prior to 5.7.3. This flaw originates from misconfigured role inheritance, leading to improper access controls.

The vulnerability arises because the AI Toolkit modifies the default ‘user’ role via an authorize.conf file containing a srchFilter entry. Due to Splunk’s use of the OR operator when combining inherited search filters, this configuration can inadvertently override more stringent filters applied to custom roles.

Consequently, users with lower privileges, who do not possess ‘admin’ or ‘power’ roles, might gain access to sensitive data that should otherwise be restricted. Splunk has rectified this issue in version 5.7.3.

As a temporary measure, organizations can disable the AI Toolkit or manually adjust the authorization.conf file to remove or supersede the srchFilter setting. However, implementing this workaround may expose the ai_agent_run_history_index to broader access, necessitating further access restrictions.

Sensitive Data Exposure via Logs (CVE-2026-20239)

A high-severity vulnerability, CVE-2026-20239 (CVSS 7.5), impacts both Splunk Enterprise and Splunk Cloud Platform. This flaw resides in the TcpChannel component, where improper output sanitization allows the logging of entire input/output buffers when socket errors occur.

Attackers who manage to gain access to the _internal index can extract sensitive information, such as session cookies and HTTP response bodies, directly from these log files. This significantly elevates the risk of credential theft and session hijacking.

Affected versions include:

  • Splunk Enterprise versions earlier than 10.2.2 and 10.0.5.
  • Splunk Cloud Platform versions preceding multiple patched releases across supported branches.

Splunk advises immediate upgrades to the latest patched versions and emphasizes the importance of restricting access to the _internal index exclusively to administrative roles.

Denial-of-Service in Splunk Archiver (CVE-2026-20240)

Another high-severity issue, CVE-2026-20240 (CVSS 7.1), affects the Splunk Archiver app. This vulnerability stems from improper input validation within the coldToFrozen.sh script, which is responsible for managing data lifecycle transitions.

A low-privileged user could exploit this flaw by providing arbitrary file paths, enabling them to rename critical directories. Such an action can render the Splunk instance inoperable, leading to a denial-of-service condition.

This vulnerability affects multiple versions of Splunk Enterprise (specifically, versions prior to 10.2.2, 10.0.5, 9.4.11, and 9.3.12) and various Splunk Cloud Platform deployments.

Organizations are urged to apply the necessary patches without delay. Alternatively, if the Splunk Archiver app is not essential, it can be disabled, though this might disrupt automated data archiving workflows.

What You Should Do

  • Upgrade Immediately: Update all affected Splunk components (Splunk Enterprise, Splunk Cloud Platform, Splunk AI Toolkit, and Splunk Archiver app) to the latest secure versions as recommended by Splunk.
  • Restrict Access: Limit access to sensitive indexes, particularly the _internal index, to administrative roles only.
  • Review Role-Based Controls: Conduct a thorough review of existing role-based access controls and inherited permissions to ensure they align with the principle of least privilege.
  • Disable Non-Essential Apps: If immediate patching is not feasible, disable vulnerable applications, such as the Splunk Archiver app, if they are not critical to operations. Be aware of potential workflow interruptions.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Hugging Face Used to Host Malware in npm Supply Chain Attack

Next Post

CISA Warns of Critical Trend Micro Apex One RCE Vulnerability Exploated in Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
GitHub Expands Malware Detection to 8 Package Registries
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us