← Back to CVE List
CVE-2026-20239NVD
Vulnerability Summary
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Splunk Splunk >= 10.0.0 and < 10.0.5
- Splunk Splunk >= 10.2.0 and < 10.2.2
- Splunk Splunk Cloud Platform >= 10.0.2503 and < 10.0.2503.13
- Splunk Splunk Cloud Platform >= 10.1.2507 and < 10.1.2507.21
- Splunk Splunk Cloud Platform >= 10.2.2510 and < 10.2.2510.11
- Splunk Splunk Cloud Platform >= 10.3.2512 and < 10.3.2512.8
- Splunk Splunk 10.0.5
- Splunk Splunk 10.2.2
- Splunk Splunk Cloud Platform 10.0.2503.13
- Splunk Splunk Cloud Platform 10.1.2507.21
- Splunk Splunk Cloud Platform 10.2.2510.11
- Splunk Splunk Cloud Platform 10.3.2512.8