CVE-2026-20239Patch(splunk / splunk)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk splunk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk
  • splunk_cloud_platform

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-24); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
splunksplunk_cloud_platform

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-24: 1Mentions · 2026-05-26: 1Mentions · 2026-05-28: 1Mentions · 2026-06-01: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 105-2405-2605-2806-01
Signal classification2 categories
Patch
375.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-241
Patch1
2026-05-261
Patch1
2026-05-281
Patch1
2026-06-011
General1
Full discourse4 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    شركة (Splunk) نزلت ٣ تحديثات أمنية للمنتجات التالية 📍 ثغرة (CVE-2026-20238 | CVSS 6.5) المنتج المتأثر: (Splunk AI Toolkit) 📍 ثغرة (CVE-2026-20239 | CVSS 7.5) المنتج المتأثر: (Splunk Enterprise) و (Splunk Cloud Platform) 📍 ثغرة (CVE-2026-20240 | CVSS 7.1) المنتج المتأثر: تطبيق (Splunk Archiver) لاتنسى التحديث اذا تستخدم احد هذه المنتجات

    Post summary

    Splunk released security updates for three CVEs (CVE‑2026‑20238, –20239, –20240) with CVSS scores 6.5, 7.5, 7.1, addressing specific products; no exploit, PoC, or active exploitation information was included.

    12039334.9K
    50.0K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Splunk ❗ CVE-2026-20240 ❗ CVE-2026-20239 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-splunk-5/ https://t.co/sLdJG15puQ

    Post summary

    Two CVEs affecting Splunk products are mentioned, but the source provides no technical details, exploit or mitigation information.

    0001195
    6.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Splunk has released security updates addressing multiple vulnerabilities, including CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240, across #Splunk Enterprise, #Splunk Cloud Platform, and #Splunk AI Toolkit. Risks of DoS conditions and sensitive data exposure. #Patch

    Post summary

    Splunk released security updates for CVE-2026-20238 through CVE-2026-20240, mitigating risks of DoS and sensitive data exposure across several platforms.

    01000228
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Splunk の脆弱性 CVE-2026-20238/20239/20240 が FIX:DoS 攻撃や機密情報漏洩の恐れ https://iototsecnews.jp/2026/05/22/splunk-patches-multiple-vulnerabilities-that-enable-dos-attack-and-exposes-sensitive-data/ Splunk の新たな脆弱性は、ロール継承時の条件結合の不備/ログ出力時のサニタイズ不足/スクリプトにおける入力検証の不備に起因します。 脆弱性 CVE-2026-20238 は、 フィルターの結合処理の誤りにより、本来は制限されるべきデータへのアクセスを許すものです。脆弱性 CVE-2026-20239 では、エラー時の不適切なログ記録により機密情報が露出する設計上の不備に起因します。脆弱性 CVE-2026-20240 は、入力値のチェック漏れから、重要なディレクトリの変更によるサービス拒否を招く恐れがあります。ご利用のチームは、ご注意ください。 #CVE202620238 #CVE202620239 #CVE202620240 #Splunk #Vulnerability

    Post summary

    Splunk released patches for CVE‑2026‑20238, 20239, and 20240, which involve filter handling, log sanitization, and input validation flaws that could allow DoS or sensitive data leakage; no active exploitation or PoC is reported.

    00000103
    489 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---
Appsplunksplunk_cloud_platform---

Explore more