Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2107 articles · 154715 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-20239PATCHED
Splunk · Splunk Enterprise

Sensitive Information Disclosure through Log Files in Splunk Enterprise

Description

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.

Affected Products

VendorProductVersions
SplunkSplunk Enterprise10.2, 10.0, 10.3.2512, 10.2.2510, 10.1.2507, 10.0.2503

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
splunksplunk cloudmitre_affected90%

References

  • https://advisory.splunk.com/advisories/SVD-2026-0503

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-20239 | Splunk Enterprise/Cloud Platform log file (SVD-2026-0503)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.2.210.0.510.3.2512.810.2.2510.1110.1.2507.2110.0.2503.13
CWECWE-532
PublishedMay 20, 2026
Last enriched1h agov2
Tags
CVE-2026-20239
Trending Score32
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALPRE-CVE
Multiple vulnerabilities in Splunk products requiring critical updates
Trending: 30
HIGHCVE-2026-20240
Denial of Service through coldToFrozen.sh Script in Splunk Enterprise
Trending: 27
MEDIUMCVE-2026-20238
Improper Access Control through Role Inheritance in Splunk AI Toolkit app
Trending: 23
HIGHCVE-2026-20204EXP
Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise
Trending: 1
HIGHCVE-2026-20205EXP
Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app
Trending: 1

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 20, 2026
Discovered by ZDM
May 20, 2026
Updated: tags
May 20, 2026
Patch Available
May 20, 2026

Version History

v2
Last enriched 1h ago
v2Tier C1h ago

Updated exploit availability to false, marked as not actively exploited, and added new CVE ID tag.

tags
via VulDB
v11h ago

Initial creation