CVE-2026-20204Patch(splunk / splunk)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk splunk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform a Remote Code Execution (RCE) by uploading a malicious file to the `$SPLUNK_HOME/var/run/splunk/apptemp` directory due to improper handling and insufficient isolation of temporary files within the `apptemp` directory.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-377

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk
  • splunk_cloud_platform

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 10 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 4 mentions (2026-04-16); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Vendors
Products
splunksplunk_cloud_platform

1 version affected across 2 products

Deep dive

Activity timeline11 mentions / 6d
01234Mentions · 2026-04-16: 4Mentions · 2026-04-17: 3Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-05-19: 1Mentions · 2026-06-14: 1Patch / Workaround · 2026-04-16: 3Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-05-19: 1Technical Details · 2026-04-16: 4Technical Details · 2026-04-17: 3Technical Details · 2026-04-23: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-14: 104-1604-1704-2204-2305-1906-14
Signal classification3 categories
Patch
654.5%
Disclosure
436.4%
General
19.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-164
Disclosure1Patch3
2026-04-173
Disclosure1Patch2
2026-04-221
General1
2026-04-231
Disclosure1
2026-05-191
Patch1
2026-06-141
Disclosure1
Full discourse11 posts
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة في منصات Splunk Enterprise و Cloud تسمح بتنفيذ هجمات عن بعد تم الإعلان عن ثغرة أمنية خطيرة تؤثر على عدة إصدارات من منصات Splunk Enterprise و Cloud، وتم تتبعها تحت رقم CVE-2026-20204. تحمل هذه الثغرة درجة خطورة عالية، مما يسمح بتنفيذ هجمات عن بعد. تؤثر هذه الثغرة على أنظمة متعددة، ويجب على المستخدمين اتخاذ إجراءات فورية لتأمين أنظمتهم. — يُنصح بـ تطبيق التصحيحات الأمنية فورًا. 🔗 للمزيد: https://cybersecuritynews.com/splunk-enterprise-and-cloud-platform-vulnerability/

    Post summary

    A new high‑severity vulnerability (CVE-2026-20204) affecting Splunk Enterprise and Cloud platforms has been announced, and users are urged to apply security patches immediately.

    00051520
    257 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Splunk fixes CVE-2026-20204, a critical RCE flaw where low-privilege users can hijack servers via temp files. Patch Enterprise and Cloud instances now! #Splunk #CyberSecurity #RCE #InfoSec #Vulnerability #PatchNow #DataSecurity https://securityonline.info/splunk-enterprise-cloud-rce-vulnerability-cve-2026-20204/ https://t.co/nVPKJVdINi

    Post summary

    Splunk announces a patch for CVE-2026-20204, a critical remote code execution flaw exploitable by low-privilege users via temp files.

    01040380
    12.3K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Splunk Enterprise及びSplunk Cloud Platformで深刻な脆弱が修正。CVE-2026-20204は低権限ユーザによる遠隔コード実行の脆弱性。アップロードされた一時ファイルの隔離不十分のため。 https://securityonline.info/splunk-enterprise-cloud-rce-vulnerability-cve-2026-20204/

    Post summary

    The post announces that CVE-2026-20204, a remote code execution flaw in Splunk Enterprise and Splunk Cloud Platform caused by inadequate isolation of uploaded temporary files, has been patched.

    00031836
    7.6K followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Disclosure

    CVE-2026-20204、CVSSなしでRCE。Splunk Enterpriseに認証不要の脆弱性。 未認証の攻撃者がコード実行可能。 ↓詳細はリプライで #脆弱性 https://t.co/2Pp0p61LFB

    Post summary

    The tweet announces a new unauthenticated RCE vulnerability (CVE‑2026‑20204) in Splunk Enterprise, with no PoC, exploit, or patch details provided.

    1000080
    275 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    🚨 CVE-2026-20204 (Splunk Enterprise <10.2.1/9.4.10/9.3.11): Any low-priv user → RCE via malicious file upload to apptemp dir. Attacker owns your SIEM → exfil all logs, blind all detection. Patched Apr 15 — most still exposed. Splunk admins: update NOW. #ZeroDay #Splunk

    Post summary

    The tweet warns of a remote code execution vulnerability (CVE-2026-20204) in older Splunk Enterprise versions and urges administrators to apply the April patch to prevent data exfiltration.

    0001054
    226 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Splunk Enterprise/Cloud の脆弱性 CVE-2026-20204 が FIX:RCE の可能性 https://iototsecnews.jp/2026/04/16/splunk-enterprise-and-cloud-platform-vulnerability-enables-remote-code-execution-attacks/ この脆弱性の主な原因は、Splunk が作成する一時ファイルの管理方法の不備にあります。脆弱性 CVE-2026-20204 (CVSS 7.1) は、Splunk Web コンポーネントが特定のディレクトリにファイルを保存する際に、それらを適切に隔離できないために発生します。管理者のような高い権限を持っていなくても、システムにログインできる一般的なユーザー・アカウントさえあれば、細工した悪意のファイルを特定の場所へアップロードすることで、サーバ上でプログラムを実行させることが可能になっています。Splunk は機密性の高いログやセキュリティ情報を扱う重要なシステムであるため、ここが侵害されると組織全体の安全が脅かされる恐れがあります。ご利用のチームは、ご注意ください。 #Cloud #CVE202620204 #Enterprise #Splunk #Vulnerability

    Post summary

    The post discloses CVE-2026-20204 as a file‑upload based RCE flaw in Splunk Web, providing CVSS 7.1 and technical details, and urges users to be cautious, but offers no PoC, exploit code, or patch specifics.

    01000116
    486 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Splunk ❗ CVE-2026-20205 ❗ CVE-2026-20204 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-splunk-4/ https://t.co/mXxe4zKS3C

    Post summary

    The tweet lists two Splunk CVEs (CVE-2026-20205 and CVE-2026-20204) and links to a site for more information, but provides no further detail.

    00001192
    6.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High severity vulnerability in #Splunk #Enterprise and #CloudPlatform. #CVE-2026-20204 CVSS: 7.1. Improper handling of temporary files allows a low-privileged user to remotely execute code #RCE ! #Patch #Patch #Patch

    Post summary

    The post alerts to CVE-2026-20204, a high‑severity RCE risk via temporary file handling, provides a CVSS score, and signals that a patch is available, but includes no exploit or active‑use details.

    01000206
    7.2K followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Critical vulnerability CVE-2026-20204 in Splunk Enterprise & Cloud platforms allows remote code execution. Immediate action required to secure systems. Link: https://thedailytechfeed.com/critical-splunk-vulnerability-cve-2026-20204-risks-remote-code-execution-urgent-updates-advised/ #Security #CVE #Splunk #Remote #Execution #Threat #Patch #Update #Risk #Protection #Network #Defense #Alert #Tech #System #Breach #Hack #Exploit #Software #Urgent

    Post summary

    A critical remote code execution vulnerability (CVE-2026-20204) has been disclosed for Splunk Enterprise and Cloud platforms, prompting immediate remediation.

    000003
    279 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20204 In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, … https://www.cve.org/CVERecord?id=CVE-2026-20204

    Post summary

    The excerpt simply discloses the affected Splunk Enterprise and Cloud Platform versions for CVE-2026-20204 without offering PoC, exploit, or mitigation details.

    00000111
    57.2K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 Critical Splunk RCE Vulnerability (#CVE-2026-20204) Exploits Insecure Temporary Files — Patch Now! + Video https://undercodetesting.com/critical-splunk-rce-vulnerability-cve-2026-20204-exploits-insecure-temporary-files-patch-now-video/ Educational Purposes!

    Post summary

    The post announces a critical Remote Code Execution flaw (CVE‑2026‑20204) in Splunk caused by insecure temporary files and urges users to apply the patch immediately, accompanied by an educational video.

    0000040
    491 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---
Appsplunksplunk10.2.0--
Appsplunksplunk_cloud_platform---

Explore more