← Back

CVE-2026-20239

nvd nist
Published: May 20, 2026Modified: Jul 23, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.

Affected (6)

2 products
Splunk
Splunk Cloud Platform
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 10.0.0 to 10.0.5
From 10.2.0 to 10.2.2
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 10.0.2503 to 10.0.2503.13
From 10.1.2507 to 10.1.2507.21
From 10.2.2510 to 10.2.2510.11
From 10.3.2512 to 10.3.2512.8

References (1)

Source: psirt@cisco.com
Vendor Advisory

Timeline

No history available yet.