CVE-2026-20240Patch(splunk / splunk)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk splunk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by exploiting the `coldToFrozen.sh` script in the `splunk_archiver` app to rename critical Splunk directories, making the instance non-functional.<br><br>The Denial of Service is possible because of missing input validation in the `coldToFrozen.sh` script, which accepts arbitrary file paths and renames them without restricting operations to safe directories.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk
  • splunk_cloud_platform

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-22); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
splunksplunk_cloud_platform

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-05-22: 2Mentions · 2026-05-24: 1Mentions · 2026-05-26: 1Mentions · 2026-05-28: 1Mentions · 2026-06-01: 1Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-24: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 105-2205-2405-2605-2806-01
Signal classification2 categories
Patch
466.7%
Disclosure
233.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-222
Patch2
2026-05-241
Patch1
2026-05-261
Patch1
2026-05-281
Disclosure1
2026-06-011
Disclosure1
Full discourse6 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    شركة (Splunk) نزلت ٣ تحديثات أمنية للمنتجات التالية 📍 ثغرة (CVE-2026-20238 | CVSS 6.5) المنتج المتأثر: (Splunk AI Toolkit) 📍 ثغرة (CVE-2026-20239 | CVSS 7.5) المنتج المتأثر: (Splunk Enterprise) و (Splunk Cloud Platform) 📍 ثغرة (CVE-2026-20240 | CVSS 7.1) المنتج المتأثر: تطبيق (Splunk Archiver) لاتنسى التحديث اذا تستخدم احد هذه المنتجات

    Post summary

    Splunk announced the release of security updates for three CVEs affecting various products, providing CVE IDs and CVSS scores but no exploit or PoC details.

    12039334.9K
    50.0K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Splunkが深刻な脆弱性を修正。DoSのCVE-2026-20240やエラー時のバッファ漏洩CVE-2026-20239、AI Toolkitの機密情報漏洩CVE-2026-20238。 https://securityonline.info/splunk-enterprise-security-advisories-cve-2026-20240-log-leak/

    Post summary

    Splunk has released patches for three critical CVEs—CVE-2026-20240 (DoS), CVE-2026-20239 (buffer leak), and CVE-2026-20238 (data leakage)—as detailed in the linked advisory.

    02051960
    7.6K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Splunk ❗ CVE-2026-20240 ❗ CVE-2026-20239 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-splunk-5/ https://t.co/sLdJG15puQ

    Post summary

    The tweet announces two CVE identifiers affecting Splunk products and directs readers to a link for additional details.

    0001195
    6.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Splunk releases coordinated patches for CVE-2026-20240 and adjacent flaws exposing raw session cookies, data filters, and triggering server DoS. #Splunk #VulnerabilityAlert #CVE202620240 #SIEM #SysAdmin #InfoSec #CyberSecurity https://securityonline.info/splunk-enterprise-security-advisories-cve-2026-20240-log-leak/ https://t.co/5BlyGa9bV8

    Post summary

    Splunk announced coordinated patches for CVE-2026‑20240, covering flaws that expose raw session cookies, data filters, and trigger server DoS, as detailed in the official advisory.

    00011345
    12.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Splunk has released security updates addressing multiple vulnerabilities, including CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240, across #Splunk Enterprise, #Splunk Cloud Platform, and #Splunk AI Toolkit. Risks of DoS conditions and sensitive data exposure. #Patch

    Post summary

    Splunk announced that security updates have been released for CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240, addressing potential DoS conditions and sensitive data exposure across its enterprise, cloud, and AI toolkit products.

    01000228
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Splunk の脆弱性 CVE-2026-20238/20239/20240 が FIX:DoS 攻撃や機密情報漏洩の恐れ https://iototsecnews.jp/2026/05/22/splunk-patches-multiple-vulnerabilities-that-enable-dos-attack-and-exposes-sensitive-data/ Splunk の新たな脆弱性は、ロール継承時の条件結合の不備/ログ出力時のサニタイズ不足/スクリプトにおける入力検証の不備に起因します。 脆弱性 CVE-2026-20238 は、 フィルターの結合処理の誤りにより、本来は制限されるべきデータへのアクセスを許すものです。脆弱性 CVE-2026-20239 では、エラー時の不適切なログ記録により機密情報が露出する設計上の不備に起因します。脆弱性 CVE-2026-20240 は、入力値のチェック漏れから、重要なディレクトリの変更によるサービス拒否を招く恐れがあります。ご利用のチームは、ご注意ください。 #CVE202620238 #CVE202620239 #CVE202620240 #Splunk #Vulnerability

    Post summary

    The article announces three new Splunk CVEs (CVE-2026-20238/20239/20240) that could enable DoS or data exposure, provides technical details, but does not report active exploitation, PoCs, or specific patches.

    00000103
    489 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---
Appsplunksplunk_cloud_platform---
Appsplunksplunk_cloud_platform10.4.2603--

Explore more