{"id":13073,"date":"2026-05-22T10:03:44","date_gmt":"2026-05-22T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/22\/splunk-patches-multiple-vulnerabilities-that-enable-dos-attack-and-exposes-sensitive-data\/"},"modified":"2026-05-22T10:03:44","modified_gmt":"2026-05-22T10:03:44","slug":"splunk-patches-multiple-vulnerabilities-that-enable-dos-attack-and-exposes-sensitive-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/22\/splunk-patches-multiple-vulnerabilities-that-enable-dos-attack-and-exposes-sensitive-data\/","title":{"rendered":"Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data"},"content":{"rendered":"<p>    Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Splunk has released security updates addressing multiple <a href=\"https:\/\/cybersecuritynews.com\/splunk-enterprise-and-cloud-platform-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities across Splunk Enterprise<\/a>, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and exposure of sensitive data.<\/p>\n<p class=\"wp-block-paragraph\">The issues, disclosed on May 20, 2026, include three tracked vulnerabilities: CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240.<\/p>\n<h3 id=\"h-splunk-ai-toolkit-access-flaw-cve-2026-20238\" class=\"wp-block-heading\"><strong>Splunk AI Toolkit Access Flaw (<a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0502\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-20238<\/a>)<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">A medium-severity flaw (CVSS 6.5) affects Splunk AI Toolkit versions below 5.7.3. The issue stems from improper access control caused by misconfigured role inheritance.<\/p>\n<p class=\"wp-block-paragraph\">Specifically, the toolkit modifies the default \u2018user\u2019 role using an\u00a0<code>authorize.conf\u00a0<\/code>file with a\u00a0<code>srchFilter<\/code>\u00a0entry.<\/p>\n<p class=\"wp-block-paragraph\">Because Splunk combines inherited search filters using the OR operator, this configuration can override more restrictive filters applied to custom roles.<\/p>\n<p class=\"wp-block-paragraph\">As a result, low-privileged users without \u2018admin\u2019 or \u2018power\u2019 roles may gain access to sensitive data that should be restricted.<\/p>\n<p class=\"wp-block-paragraph\">Splunk has fixed this issue in version 5.7.3. As a temporary mitigation, organizations can disable the AI Toolkit or manually modify the\u00a0<code>authorization.conf<\/code>\u00a0file to remove or override the<code>\u00a0srchFilter<\/code>\u00a0setting.<\/p>\n<p class=\"wp-block-paragraph\">However, this workaround may expose the\u00a0<code>ai_agent_run_history_index<\/code>\u00a0to broader access, requiring additional restrictions.<\/p>\n<h3 id=\"h-sensitive-data-exposure-via-logs-cve-2026-20239\" class=\"wp-block-heading\"><strong>Sensitive Data Exposure via Logs (<a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0503\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-20239<\/a>)<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">A high-severity vulnerability (CVSS 7.5) impacts Splunk Enterprise and Splunk Cloud Platform.<\/p>\n<p class=\"wp-block-paragraph\">The flaw is caused by improper output sanitization in the\u00a0TcpChannel\u00a0component, which logs the entire input\/output buffer when socket errors occur.<\/p>\n<p class=\"wp-block-paragraph\">Attackers with access to the\u00a0<code>_internal<\/code>\u00a0index can retrieve sensitive information such as session cookies and HTTP response bodies from log files. This significantly increases the risk of<a href=\"https:\/\/cybersecuritynews.com\/splunk-enterprise-for-windows-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> credential theft and session hijacking<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Affected versions include:<\/p>\n<ul class=\"wp-block-list\">\n<li>Splunk Enterprise below 10.2.2 and 10.0.5.\n<\/li>\n<li>Splunk Cloud Platform versions before multiple patched releases across supported branches.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Splunk recommends upgrading to the latest patched versions and restricting access to the\u00a0_internal\u00a0index to administrative roles only.<\/p>\n<h3 id=\"h-denial-of-service-in-splunk-archiver-cve-2026-20240\" class=\"wp-block-heading\"><strong>Denial-of-Service in Splunk Archiver (<a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0504\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-20240<\/a>)<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">Another high-severity issue (CVSS 7.1) affects the Splunk Archiver app due to improper input validation in the\u00a0<code>coldToFrozen.sh<\/code>\u00a0script. This script is used for managing data lifecycle transitions.<\/p>\n<p class=\"wp-block-paragraph\">A low-privileged user can exploit this flaw by supplying arbitrary file paths, allowing them to rename critical directories. This can render the Splunk instance inoperable, resulting in a <a href=\"https:\/\/cybersecuritynews.com\/modsecurity-dos-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial-of-service condition<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability affects multiple versions of Splunk Enterprise (before 10.2.2, 10.0.5, 9.4.11, and 9.3.12) and Splunk Cloud Platform deployments.<\/p>\n<p class=\"wp-block-paragraph\">Organizations are advised to<a href=\"https:\/\/cybersecuritynews.com\/splunk-enterprise-for-windows-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\"> apply patches immediately<\/a> or turn off the Splunk Archiver app if it is not required. However, turning off the app may interrupt automated data archiving workflows.<\/p>\n<p class=\"wp-block-paragraph\">Splunk strongly urges users to:<\/p>\n<ul class=\"wp-block-list\">\n<li>Upgrade all affected components to the latest secure versions.<\/li>\n<li>Restrict access to sensitive indexes such <code>as\u00a0_internal<\/code>.<\/li>\n<li>Review role-based access controls and inherited permissions.<\/li>\n<li>Disable vulnerable apps if patches cannot be applied immediately.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">These vulnerabilities highlight the risks associated with misconfigured access controls, insufficient input validation, and insecure logging practices.<\/p>\n<p class=\"wp-block-paragraph\">Timely patching and proper configuration management remain critical to securing Splunk environments against exploitation.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/splunk-patches-multiple-vulnerabilities\/\">Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/splunk-patches-multiple-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and exposure of sensitive data. The issues, disclosed on May 20, 2026, include three tracked vulnerabilities: CVE-2026-20238, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-13073","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13073"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13073"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13073\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13073"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13073"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13073"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}