CVE-2026-20202Disclouser(splunk / splunk)

LOWCVSS 6.6 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a specially crafted username that includes a null byte or a non-UTF-8 percent-encoded byte due to improper input validation.<br><br>This could lead to inconsistent conversion of usernames into a proper format for storage and account management inconsistencies, such as being unable to edit or delete affected users.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-176

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk
  • splunk_cloud_platform

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclouser: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-16); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
splunksplunk_cloud_platform

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1Mentions · 2026-05-04: 1PoC Mentioned / Linked · 2026-05-04: 1Technical Details · 2026-04-17: 104-1604-1705-04
Signal classification3 categories
Disclouser
133.3%
Disclosure
133.3%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclouser1
2026-04-171
Disclosure1
2026-05-041
PoC1
Full discourse3 posts
  • 𝔸𝕪𝕚𝕣𝕒𝕗 ℝ𝕒𝕙𝕞𝕒𝕟@mahfujwhh
    Disclosure

    Alhamdulliah ! Got CVE-2026-20202 assigned 🎯 Discovered an input validation issue in Splunk that could break user account management. https://www.cve.org/CVERecord?id=CVE-2026-20202 #CVE #infosec #bugbounty

    Post summary

    The post announces the assignment of CVE-2026-20202, noting an input validation flaw in Splunk that may disrupt user account management, but provides no PoC, exploit, or patch information.

    000161588
    1.9K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE-2026-20202 Exploit Exposed: How Bug Bounty Hunters Are Leveraging This Zero-Day - Full Technical Deep Dive + Video https://undercodetesting.com/cve-2026-20202-exploit-exposed-how-bug-bounty-hunters-are-leveraging-this-zero-day-full-technical-deep-dive-video/ Educational Purposes!

    Post summary

    The post promotes a video that deep‑dives into CVE‑2026‑20202, likely showcasing a proof‑of‑concept exploit, but it does not assert active exploitation, provide tooling, patches, or technical specifics.

    0000081
    518 followersView on X
  • CVE@CVEnew
    Disclouser

    CVE-2026-20202 In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20,… https://www.cve.org/CVERecord?id=CVE-2026-20202

    Post summary

    The text announces CVE-2026-20202 and lists vulnerable Splunk version ranges but lacks details on exploitation, patches, or technical characteristics.

    00000117
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---
Appsplunksplunk_cloud_platform---

Explore more