Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GitLab Suspends Nightmare-Eclipse After GitHub Ban
May 27, 2026
CERT-In: Patch Critical Vulnerabilities in Systems Within
May 27, 2026
BIND 9 Flaws Expose Servers & Resolvers to Software Vulnerabilities
May 27, 2026
Home/CyberSecurity News/Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and
CyberSecurity News

Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and

Splunk has released security updates for Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit. These updates address multiple vulnerabilities that could lead to denial-of-service (DoS)...

Marcus Rodriguez
Marcus Rodriguez
May 22, 2026 2 Min Read
14 0

Splunk has released security updates for Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit. These updates address multiple vulnerabilities that could lead to denial-of-service (DoS) conditions and sensitive data exposure.

Table Of Content

  • Splunk AI Toolkit Access Flaw (CVE-2026-20238)
  • Sensitive Data Exposure via Logs (CVE-2026-20239)
  • Denial-of-Service in Splunk Archiver (CVE-2026-20240)

The issues, disclosed on May 20, 2026, include three tracked vulnerabilities: CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240.

Splunk AI Toolkit Access Flaw (CVE-2026-20238)

A medium-severity flaw (CVSS 6.5) affects Splunk AI Toolkit versions below 5.7.3. The issue stems from improper access control caused by misconfigured role inheritance.

Specifically, the toolkit modifies the default ‘user’ role using an authorize.conf file with a srchFilter entry.

Because Splunk combines inherited search filters using the OR operator, this configuration can override more restrictive filters applied to custom roles.

As a result, low-privileged users without ‘admin’ or ‘power’ roles may gain access to sensitive data that should be restricted.

Splunk has fixed this issue in version 5.7.3. As a temporary mitigation, organizations can disable the AI Toolkit or manually modify the authorization.conf file to remove or override the srchFilter setting.

However, this workaround may expose the ai_agent_run_history_index to broader access, requiring additional restrictions.

Sensitive Data Exposure via Logs (CVE-2026-20239)

A high-severity vulnerability (CVSS 7.5) impacts Splunk Enterprise and Splunk Cloud Platform.

The flaw is caused by improper output sanitization in the TcpChannel component, which logs the entire input/output buffer when socket errors occur.

Attackers with access to the _internal index can retrieve sensitive information such as session cookies and HTTP response bodies from log files. This significantly increases the risk of credential theft and session hijacking.

Affected versions include:

  • Splunk Enterprise below 10.2.2 and 10.0.5.
  • Splunk Cloud Platform versions before multiple patched releases across supported branches.

Splunk recommends upgrading to the latest patched versions and restricting access to the _internal index to administrative roles only.

Denial-of-Service in Splunk Archiver (CVE-2026-20240)

Another high-severity issue (CVSS 7.1) affects the Splunk Archiver app due to improper input validation in the coldToFrozen.sh script. This script is used for managing data lifecycle transitions.

A low-privileged user can exploit this flaw by supplying arbitrary file paths, allowing them to rename critical directories. This can render the Splunk instance inoperable, resulting in a denial-of-service condition.

The vulnerability affects multiple versions of Splunk Enterprise (before 10.2.2, 10.0.5, 9.4.11, and 9.3.12) and Splunk Cloud Platform deployments.

Organizations are advised to apply patches immediately or turn off the Splunk Archiver app if it is not required. However, turning off the app may interrupt automated data archiving workflows.

Splunk strongly urges users to:

  • Upgrade all affected components to the latest secure versions.
  • Restrict access to sensitive indexes such as _internal.
  • Review role-based access controls and inherited permissions.
  • Disable vulnerable apps if patches cannot be applied immediately.

These vulnerabilities highlight the risks associated with misconfigured access controls, insufficient input validation, and insecure logging practices.

Timely patching and proper configuration management remain critical to securing Splunk environments against exploitation.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Hackers Use Hugging Face for npm Supply Host Second-Stage

Next Post

CISA Warns: Trend Micro Apex One Vulner Vulnerability Exploited

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Angular Language Service Flaws Enable Remote Code Execution
May 26, 2026
Quasar Linux RAT Targets Developers via Fileless eBPF
May 26, 2026
China-Linked Hackers Target SEA Edge Routers with Southeast Asian
May 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us