CVE-2026-20239: Sensitive Information Disclosure through Log Files in Splunk Enterprise
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the internal index could view session cookies and response bodies that contain sensitive data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.2 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.5 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.3.2512.8 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.11 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.21 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.0.2503.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20239?
CVE-2026-20239 is classified as a high severity vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2026-20239?
To fix CVE-2026-20239, upgrade your Splunk Enterprise or Splunk Cloud Platform to the latest versions that address the vulnerability.
Who is affected by CVE-2026-20239?
CVE-2026-20239 affects users of Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, among others.
What type of information is disclosed in CVE-2026-20239?
CVE-2026-20239 can lead to the exposure of sensitive information contained within log files accessed through the _internal index.
What should I do if I can't upgrade due to CVE-2026-20239?
If you cannot upgrade, limit user roles and access to the _internal index to mitigate the risk associated with CVE-2026-20239.