PT-2026-20468 · Splunk · Splunk Enterprise+1
Anton
·
Published
2026-02-18
·
Updated
2026-04-16
·
CVE-2026-20137
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9
Splunk Cloud Platform versions prior to 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122
Description
A user with limited privileges, lacking the 'admin' or 'power' roles within Splunk, may be able to circumvent security measures designed to protect against potentially harmful SPL commands. This occurs when creating a Data Model that incorporates an injected SPL query within an object. The bypass is achieved through a path traversal flaw.
Recommendations
Update Splunk Enterprise to version 10.2.0 or later.
Update Splunk Enterprise to version 10.0.3 or later.
Update Splunk Enterprise to version 9.4.5 or later.
Update Splunk Enterprise to version 9.3.7 or later.
Update Splunk Enterprise to version 9.2.9 or later.
Update Splunk Cloud Platform to version 10.1.2507.0 or later.
Update Splunk Cloud Platform to version 10.0.2503.9 or later.
Update Splunk Cloud Platform to version 9.3.2411.112 or later.
Update Splunk Cloud Platform to version 9.3.2408.122 or later.
Fix
Information Disclosure
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Splunk Cloud Platform
Splunk Enterprise