CVE-2026-20163Disclosure(splunk / splunk)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk splunk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that contains the high-privilege capability `edit_cmd` could execute arbitrary shell commands using the `unarchive_cmd` parameter for the `/splunkd/__upload/indexing/preview` REST endpoint.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk
  • splunk_cloud_platform

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 4 mentions (2026-03-12); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
splunksplunk_cloud_platform

Deep dive

Activity timeline12 mentions / 6d
01234Mentions · 2026-03-12: 4Mentions · 2026-03-13: 4Mentions · 2026-03-15: 1Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-04-16: 1Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 3Technical Details · 2026-03-19: 1Technical Details · 2026-04-16: 103-1203-1303-1503-1903-2004-16
Signal classification3 categories
Disclosure
758.3%
Patch
325.0%
General
216.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-124
Disclosure1General1Patch2
2026-03-134
Disclosure4
2026-03-151
Disclosure1
2026-03-191
Disclosure1
2026-03-201
General1
2026-04-161
Patch1
Full discourse12 posts
  • Gray Hats@the_yellow_fall
    Patch

    Splunk warns of a high-severity RCE flaw (CVE-2026-20163) in its REST API. Attackers with edit_cmd rights can execute arbitrary commands. Patch immediately. https://securityonline.info/high-privilege-havoc-splunk-patches-rce-flaw-lurking-in-file-previews/ https://t.co/rXBaz4X09u

    Post summary

    Splunk announces a high‑severity RCE flaw (CVE‑2026‑20163) in its REST API that allows attackers with edit_cmd rights to run arbitrary commands, urging visitors to patch immediately.

    1712483.8K
    10.6K followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    Critical Splunk RCE Vulnerability (CVE-2026–20163) Lets Attackers Run Shell Commands on Your Server https://medium.com/@EternalSec/critical-splunk-rce-vulnerability-cve-2026-20163-lets-attackers-run-shell-commands-on-your-server-244fcbe3497d?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The text announces a newly disclosed critical Remote Code Execution vulnerability in Splunk (CVE‑2026‑20163) that would allow attackers to run shell commands on affected servers. No PoC, exploit tool, or active exploitation claims are provided.

    010125708
    40.3K followersView on X
  • Trustle Security@TrustleSecurity
    Disclosure

    Tracked as CVE-2026-20163, Splunk systems are at risk from a remote command execution (RCE) vulnerability, allowing bad actors to carry out arbitrary shell commands directly on the host operating system. 🔗 https://tinyurl.com/3c9xx9wd #cybersecurity #infosec #itsecurity

    Post summary

    The post announces that Splunk is susceptible to a remote command execution vulnerability (CVE-2026-20163) that could allow attackers to run arbitrary shell commands on the host OS, but no exploit details, patches, or active use are indicated.

    00050108
    62 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Splunk の RCE 脆弱性 CVE-2026-20163 が FIX:REST API における適切なサニタイズ https://iototsecnews.jp/2026/03/12/splunk-rce-vulnerability-exposes-systems-to-arbitrary-shell-command-execution-by-attackers/ Splunk Enterprise/Cloud Platform において、サーバ OS 上での任意のコマンド実行を許す恐れのある、脆弱性 CVE-2026-20163 (CVSS 8.0) が発見されました。この問題の原因は、ファイル・アップロード時のプレビュー機能における、入力値に対する不適切な無害化にあります。 特定の API エンドポイントに対して、攻撃者が不正な命令を埋め込んだリクエストを送信すると、Splunk によりシステム・コマンドとして実行されてしまいます。ただし、この脆弱性の悪用には、管理者レベルの高権限 (edit_cmd 権限) が必要なため、CVSS 値は 8.0 と評価されています。ご利用のチームは、ご注意ください。 #CVE202620163 #Splunk #Vulnerability

    Post summary

    The article announces the discovery of CVE‑2026‑20163, a high‑risk RCE in Splunk Enterprise/Cloud via unsanitized preview handling during file upload, and highlights the required edit_cmd privilege for exploitation.

    01000141
    484 followersView on X
  • ✮ Cymon Skinner ✮@CymonSkinner
    Patch

    Splunk has issued urgent patches for critical RCE vulnerabilities like CVE-2026-20163 and clear-text token leaks that expose systems to unauthorised access. Attackers with elevated privileges can execute arbitrary commands via insecure REST endpoints, while unencrypted tokens risk credential theft. CISOs, prioritise immediate upgrades to versions 10.2.0+ and enforce least privilege roles to safeguard your SOC. For Microsoft Sentinel users seeking secure, AI-powered alternatives with no KQL needed, discover SecQubes Harvey bot for flawless triage. Stay resilient. #CyberSecurity #SOC #Splunk

    Post summary

    The statement highlights urgent patches for critical RCE vulnerabilities in Splunk and recommends immediate upgrades and least privilege enforcement.

    0000046
    713 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-20163: Splunk Command Injection Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q047JXmQ0

    Post summary

    The excerpt merely lists a CVE title and a link without providing any substantive details or actionable information.

    0000029
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20163 In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.… https://www.cve.org/CVERecord?id=CVE-2026-20163

    Post summary

    CVE-2026-20163 affects certain Splunk Enterprise and Cloud Platform versions, but the brief notice provides no details on exploitation, patching, or technical nature of the flaw.

    00000154
    56.7K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Splunk ❗ CVE-2026-20163 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-splunk-3/ https://t.co/JjRebXOYLC

    Post summary

    The post advertises a newly identified Splunk vulnerability, CVE-2026-20163, and points to external links for additional information.

    00000124
    6.6K followersView on X
  • Bug Bounty Shorts@BugBountyShorts
    Disclosure

    🔗 Read more: https://medium.com/@EternalSec/critical-splunk-rce-vulnerability-cve-2026-20163-lets-attackers-run-shell-commands-on-your-server-244fcbe3497d?source=rss------bug_bounty-5

    Post summary

    The post announces a critical Splunk RCE vulnerability (CVE-2026‑20163) that permits attackers to execute shell commands on a server. No details are provided about patches, exploitation status, or a PoC.

    0000038
    63 followersView on X
  • Annexus Technologies@annexustech
    Patch

    🚨 Splunk RCE Alert (CVE-2026-20163) – Critical flaw allows high-privilege users to execute arbitrary shell commands via the REST API preview endpoint. Update to fixed versions or remove edit_cmd from roles immediately. #CyberSecurity #Splunk #RCE https://cybersecuritynews.com/splunk-rce-vulnerability-2/?utm_source=twitter&utm_medium=Zoho+Social

    Post summary

    The post alerts readers to a critical RCE in Splunk (CVE-2026-20163) that allows high‑privilege users to execute shell commands via a REST API endpoint, and it urges immediate patching or removal of the edit_cmd capability.

    0000074
    1.1K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    CVE-2026-20163: High severity RCE in Splunk Enterprise and Cloud allows remote arbitrary shell command execution via improper input handling in system previews. CVSS 8.0. Admins should review advisories. https://threatcluster.io/cluster/critical-splunk-rce-vulnerability-exposes-systems-to-attacks-1d600442

    Post summary

    The statement announces CVE‑2026‑20163, a high‑severity RCE flaw in Splunk, offering technical details and a CVSS score but no PoC, exploit, or active exploitation evidence, simply urging admins to consult advisories.

    0000054
    100 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-20163 - Splunk - Splunk Enterprise - https://www.redpacketsecurity.com/cve-alert-cve-2026-20163-splunk-splunk-enterprise/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-20163 #splunk #splunk-enterprise

    Post summary

    The post is a short CVE alert that only links to an external site, providing no additional exploitation, patch, or technical information.

    0000089
    3.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---
Appsplunksplunk_cloud_platform---

Explore more