CVE-2026-20296
HIGH 8.3In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing Language (SPL) searches on their behalf as `splunk-system-user`, allowing for access to stored credentials and indexed data.<br><br>The vulnerability is possible because Deployment Server endpoints in Splunk Web do not validate Cross-Site Request Forgery (CSRF) tokens on GET requests, and caller-supplied input is not correctly neutralized before it is placed into an SPL search.
Severe if exploited (CVSS 8.3), but no known exploitation and low modeled probability. Patch on a normal cadence.
Exploitation likelihood
0.2%chance of exploitation in 30 days · 14th percentile
Impact if exploited
8.3CVSS 3.1 · HIGH
- ConfidentialityHigh
- IntegrityHigh
- AvailabilityLow
What an attacker needs
- ✓Access: Reachable over the network — no local access needed
- ✓Privileges: No account or privileges required
- ⚠User interaction: A user must take an action (click / open a file)
- ✓Complexity: No special conditions — reliably repeatable
✓ lowers the bar for an attacker · ⚠ raises it
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-20296/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-20296/poc.json
Weakness (CWE)
- CWE-352: The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Known Affected Software Configurations
| Vendor | Product | Version range |
|---|---|---|
| Splunk | Splunk | ≥ 9.4.0 and < 9.4.13 |
| Splunk | Splunk | ≥ 10.0.0 and < 10.0.8 |
| Splunk | Splunk | ≥ 10.2.0 and < 10.2.5 |
| Splunk | Splunk | 10.4.0 |
| Splunk | Splunk Cloud Platform | ≥ 10.1.2507 and < 10.1.2507.24 |
| Splunk | Splunk Cloud Platform | ≥ 10.2.2510 and < 10.2.2510.18 |
| Splunk | Splunk Cloud Platform | ≥ 10.3.2512 and < 10.3.2512.16 |
| Splunk | Splunk Cloud Platform | ≥ 10.4.2604 and < 10.4.2604.7 |
All CVSS metrics
- HIGH 8.3 v3.1 · CNA Primary
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L - HIGH 8.3 v3.1 · NVD Secondary
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L