CVE-2026-20240: Denial of Service through coldToFrozen.sh Script in Splunk Enterprise
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by exploiting the coldToFrozen.sh script in the splunkarchiver app to rename critical Splunk directories, making the instance non-functional.<br><br>The Denial of Service is possible because of missing input validation in the coldToFrozen.sh script, which accepts arbitrary file paths and renames them without restricting operations to safe directories.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.2 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.5 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.11 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.3.12 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.4.2603.1 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.3.2512.9 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.11 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.21 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.0.2503.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 9.3.2411.129
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20240?
CVE-2026-20240 has been classified as a low-severity denial of service vulnerability.
How do I fix CVE-2026-20240?
To fix CVE-2026-20240, update Splunk Enterprise or Splunk Cloud Platform to the latest version beyond the specified vulnerable releases.
Which software versions are affected by CVE-2026-20240?
CVE-2026-20240 affects Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, as well as certain versions of Splunk Cloud Platform.
What exploits are associated with CVE-2026-20240?
CVE-2026-20240 could be exploited by a low-privileged user to execute denial of service attacks through the coldToFrozen.sh script.
Is CVE-2026-20240 present in Splunk Cloud Platform?
Yes, CVE-2026-20240 is present in multiple versions of Splunk Cloud Platform prior to 10.4.2603.1.