PT-2026-33064 · Splunk · Splunk Cloud Platform+1
Published
2026-04-15
·
Updated
2026-05-04
·
CVE-2026-20202
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.2.2
Splunk Enterprise versions prior to 10.0.5
Splunk Enterprise versions prior to 9.4.10
Splunk Enterprise versions prior to 9.3.11
Splunk Cloud Platform versions prior to 10.4.2603.0
Splunk Cloud Platform versions prior to 10.3.2512.6
Splunk Cloud Platform versions prior to 10.2.2510.10
Splunk Cloud Platform versions prior to 10.1.2507.20
Splunk Cloud Platform versions prior to 10.0.2503.13
Splunk Cloud Platform versions prior to 9.3.2411.127
Description
Improper input validation allows a user with a role containing the high-privilege capability
edit user to create a specially crafted username containing a null byte or a non-UTF-8 percent-encoded byte. This results in inconsistent conversion of usernames for storage, leading to account management inconsistencies, such as the inability to edit or delete the affected users.Recommendations
Update Splunk Enterprise to version 10.2.2, 10.0.5, 9.4.10, or 9.3.11 depending on the current installation branch.
Update Splunk Cloud Platform to version 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, or 9.3.2411.127 depending on the current installation branch.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Cloud Platform
Splunk Enterprise