CVE-2026-20140Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-02-20); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-02-19: 1Mentions · 2026-02-20: 4Mentions · 2026-02-23: 2Mentions · 2026-02-26: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 2Patch / Workaround · 2026-02-23: 2Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 2Technical Details · 2026-02-23: 1Technical Details · 2026-02-26: 102-1902-2002-2302-26
Signal classification3 categories
Patch
450.0%
Disclosure
337.5%
General
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-191
Patch1
2026-02-204
Disclosure2General1Patch1
2026-02-232
Patch2
2026-02-261
Disclosure1
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Patch

    Splunk Enterprise Windows flaws (CVSS 7.7) CVE-2026-20143 & CVE-2026-20140 allow system takeover via DLL and Python search path hijacking. Patch immediately. #Splunk #CyberSecurity #InfoSec #WindowsSecurity #DLLHijacking #LPE #PatchNow https://securityonline.info/splunk-windows-flaws-expose-servers-to-system-takeover/

    Post summary

    Splunk Enterprise Windows flaws CVE-2026-20143 and CVE-2026-20140 enable system takeover via DLL and Python path hijacking, and a patch is urgently recommended.

    00023309
    10.3K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Splunk ❗ CVE-2026-20143 ❗ CVE-2026-20140 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-splunk-3/ https://t.co/4M8UQYUHbi

    Post summary

    The tweet announces two new CVEs (CVE-2026-20143 and CVE-2026-20140) affecting Splunk products and points to an external site for additional information.

    01010157
    6.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Splunk の脆弱性 CVE-2026-20140 が FIX:DLL サイドローディング攻撃による SYSTEM 権限昇格 https://iototsecnews.jp/2026/02/20/splunk-enterprise-for-windows-vulnerability-let-attackers-hijack-dlls-and-gain-system-access/ Windows 版の Splunk Enterprise において、ローカルの低権限ユーザーが管理者権限 (SYSTEM 権限) を奪取できてしまう深刻な脆弱性が公表されました。この問題の根本原因は、プログラムが実行に必要な部品 (DLLファイル) を探す際の検索順序が適切に制御されていないことにあります (CWE-427)。Windows 版の Splunk が特定のフォルダから DLL を読み込もうとする際に、その場所に悪意のある DLL を、あらかじめ置いておくことで、本来のプログラムに代わって攻撃者のコードを実行させてしまう DLLサイドローディング という手法が成立します。ご利用のチームは、ご注意ください。 #CVE202620140 #Splunk #Vulnerability

    Post summary

    A new Windows Splunk Enterprise vulnerability (CVE‑2026‑20140) allows local low‑privileged users to gain SYSTEM privilege via DLL side‑loading; the post details the flaw but does not mention PoC, exploit code, or patches.

    01000151
    485 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Splunk Enterprise for Windows: DLL Hijacking Bug Lets Low-Priv Users Get SYSTEM (CVE-2026-20140) A high-severity DLL search-order hijacking flaw in Splunk Enterprise for Windows (CVE-2026-20140, CVSS 7.7) lets a low-privileged local user plant a malicious DLL so the Splunk service loads it on restart and executes attacker code as SYSTEM. Upgrade to fixed releases (10.2.0 / 10.0.3 / 9.4.8 / 9.3.9 / 9.2.12) and restrict write permissions on system-drive directories to reduce hijack paths. 🎯 Target: Global/Enterprise (Windows + Splunk) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/splunk-enterprise-for-windows-vulnerability/

    Post summary

    A DLL search‑order hijacking flaw (CVE‑2026‑20140) allows low‑privileged local users on Splunk Enterprise for Windows to gain SYSTEM privileges; patches are available and users are advised to upgrade and restrict write permissions.

    0000161
    174 followersView on X
  • Alborz Safe@EthicalSafe
    Patch

    نسخه های آسیب پذیر Splunk با کد شناسایی CVE-2026-20140 و نحوه امن سازی https://t.co/lft9QeqdO8

    Post summary

    The tweet identifies vulnerable Splunk versions for CVE-2026-20140 and directs readers to a link for securing them.

    0000042
    4 followersView on X
  • Alborz Safe@EthicalSafe
    Patch

    برای Splunk Enterprise ، آسیب پذیری با کد شناسایی CVE-2026-20140 و از نوع privilege escalation منتشر شده است. هکر ها می توانند با استفاده از تکنیک DLL search-order hijacking ، دسترسی خود را به یوزر system ارتقا دهد. برای امن سازی پچ نمایید. https://t.co/xSs8qr6ZAY

    Post summary

    The post announces a privilege‑escalation vulnerability (CVE‑2026‑20140) in Splunk Enterprise, explains the DLL search‑order hijacking technique, and urges users to apply a patch.

    0000053
    4 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    General

    "# CVE-2026–20140: High-Severity Privilege Escalation in Splunk Enterprise for Windows" by Zeliha Zengin #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@zeliharich/cve-2026-20140-high-severity-privilege-escalation-in-splunk-enterprise-for-windows-15e08e519d38

    Post summary

    The tweet simply announces the CVE‑2026‑20140 privilege escalation issue in Splunk Enterprise for Windows, with no accompanying technical detail, proof of concept, patch information, or active exploitation evidence.

    0000040
    461 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Splunk Enterprise for Windows Bug Lets Attackers Hijack DLL Load to Gain SYSTEM A high-severity local privilege escalation flaw (CVE-2026-20140, CVSS 7.7) allows DLL search-order hijacking so a low-privileged user can plant a malicious DLL that Splunk loads on service restart, executing as SYSTEM. Patch by upgrading to fixed versions (10.2.0 / 10.0.3 / 9.4.8 / 9.3.9 / 9.2.12) and restrict write access on system-drive paths to reduce hijack opportunities. 🎯 Target: Global/Enterprise (Windows Splunk deployments) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/splunk-enterprise-for-windows-vulnerability/

    Post summary

    CVE‑2026‑20140 is a local privilege escalation vulnerability in Splunk Enterprise for Windows that allows DLL search‑order hijacking; patching to the listed versions or restricting write access mitigates the issue.

    0000033
    174 followersView on X

Explore more