logo

Splunk Patches High-Severity Bugs Granting DoS and Internal Log Leaks

ID: a5de41b9-a040-5ec8-9536-0921942f872a

STIX ID: report--a5de41b9-a040-5ec8-9536-0921942f872a

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Ddos

...
...

Splunk published coordinated security advisories for three vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit (CVE-2026-20240, CVE-2026-20239, CVE-2026-20238). The issues permit low-privileged users to rename critical system directories causing complete Denial of Service, cause raw network I/O buffers (including session cookies and cleartext HTTP bodies) to be written to an internal log index, and override role filters to bypass access controls; Splunk provides fixed versions and workarounds (disabling apps or editing configs) as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.