Splunk Patches Multiple Vulnerabilities that Enable DOS Attacks and Expose Sensitive Data
ID: 48fe2458-839c-5a2d-9560-b34e1fddbf83
STIX ID: report--48fe2458-839c-5a2d-9560-b34e1fddbf83
Feed Name: cybersecurityNews.com
Splunk published fixes for three vulnerabilities (CVE-2026-20238, CVE-2026-20239, CVE-2026-20240) impacting the Splunk AI Toolkit, Splunk Enterprise/Cloud, and the Splunk Archiver. Issues include misconfigured role inheritance allowing unauthorized data access, insecure TcpChannel logging exposing session cookies and HTTP bodies in the _internal index, and a coldToFrozen.sh path-manipulation leading to denial-of-service. Splunk recommends immediate patching to the fixed versions, restricting access to sensitive indexes, reviewing RBAC, and disabling vulnerable apps if patches cannot be applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
