CVE-2026-20238Patch(splunk / ai_toolkit)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk ai_toolkit systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ai_toolkit

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-05-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
ai_toolkit

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-24: 1Mentions · 2026-05-26: 1Mentions · 2026-05-28: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 105-2405-2605-28
Signal classification1 categories
Patch
3100.0%
Referenced assets1 URL
Full discourse3 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    شركة (Splunk) نزلت ٣ تحديثات أمنية للمنتجات التالية 📍 ثغرة (CVE-2026-20238 | CVSS 6.5) المنتج المتأثر: (Splunk AI Toolkit) 📍 ثغرة (CVE-2026-20239 | CVSS 7.5) المنتج المتأثر: (Splunk Enterprise) و (Splunk Cloud Platform) 📍 ثغرة (CVE-2026-20240 | CVSS 7.1) المنتج المتأثر: تطبيق (Splunk Archiver) لاتنسى التحديث اذا تستخدم احد هذه المنتجات

    Post summary

    Splunk announced three security updates addressing CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240, providing CVSS scores and urging users to apply the patches; no PoC or exploitation details are included.

    12039334.9K
    50.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Splunk has released security updates addressing multiple vulnerabilities, including CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240, across #Splunk Enterprise, #Splunk Cloud Platform, and #Splunk AI Toolkit. Risks of DoS conditions and sensitive data exposure. #Patch

    Post summary

    The post announces that Splunk has released patches for CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240, noting risks of DoS and data exposure.

    01000228
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Splunk の脆弱性 CVE-2026-20238/20239/20240 が FIX:DoS 攻撃や機密情報漏洩の恐れ https://iototsecnews.jp/2026/05/22/splunk-patches-multiple-vulnerabilities-that-enable-dos-attack-and-exposes-sensitive-data/ Splunk の新たな脆弱性は、ロール継承時の条件結合の不備/ログ出力時のサニタイズ不足/スクリプトにおける入力検証の不備に起因します。 脆弱性 CVE-2026-20238 は、 フィルターの結合処理の誤りにより、本来は制限されるべきデータへのアクセスを許すものです。脆弱性 CVE-2026-20239 では、エラー時の不適切なログ記録により機密情報が露出する設計上の不備に起因します。脆弱性 CVE-2026-20240 は、入力値のチェック漏れから、重要なディレクトリの変更によるサービス拒否を招く恐れがあります。ご利用のチームは、ご注意ください。 #CVE202620238 #CVE202620239 #CVE202620240 #Splunk #Vulnerability

    Post summary

    Splunk disclosed that CVE-2026-20238/20239/20240 have been fixed; the vulnerabilities stem from role inheritance, log sanitization, and input validation flaws that could enable DoS or data leaks, but no PoC, exploit, or active‑exploitation details are offered.

    00000103
    489 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunkai_toolkit---

Explore more