CVE-2026-20238: Improper Access Control through Role Inheritance in Splunk AI Toolkit app
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through srchFilter configurations on custom roles.<br><br>The app contains an authorize.conf configuration file with a srchFilter entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the OR SPL operator, the injected filter overrides more restrictive filters on child roles.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk AI Toolkit appto a version that resolves this vulnerability.Fixed in 5.7.3 - Configuration
In Splunk AI Toolkit authorize.conf, remove or change the srchFilter entry that modifies the built-in ‘user’ role so that srchFilter-based restrictions on custom roles cannot be overridden through role inheritance and OR SPL operator behavior.
Splunk AI Toolkit app (authorize.conf) srchFilter (for built-in ‘user’ role) = Remove/adjust the srchFilter entry that modifies the built-in ‘user’ role to prevent inheriting search filters from being overridden via OR SPL behavior.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20238?
CVE-2026-20238 has a low severity related to improper access control through role inheritance.
How do I fix CVE-2026-20238?
To fix CVE-2026-20238, upgrade the Splunk AI Toolkit to version 5.7.3 or later.
What is the impact of CVE-2026-20238?
CVE-2026-20238 allows low-privileged users to access confidential data restricted by `srchFilter` configurations.
Which versions are affected by CVE-2026-20238?
CVE-2026-20238 affects all versions of Splunk AI Toolkit below 5.7.3.
Who is vulnerable to CVE-2026-20238?
Low-privileged users without 'admin' or 'power' roles in the Splunk AI Toolkit are vulnerable to CVE-2026-20238.