
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20138 is a sensitive information disclosure vulnerability in Splunk Enterprise affecting Search Head Cluster (SHC) deployments. In affected versions, a user with a role granting access to the Splunk _internal index can view the integrationKey, secretKey, and appSecretKey secrets generated by the Duo Two-Factor Authentication for Splunk Enterprise integration in plain text. The vulnerability affects Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11. It was disclosed on February 18, 2026, and carries a CVSS v3.1 base score of 4.9 (Medium) (Splunk Advisory).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File), meaning Splunk Enterprise improperly writes Duo 2FA secrets — specifically integrationKey, secretKey, and appSecretKey — into the _internal index in plaintext rather than masking or encrypting them. Exploitation requires network access and a high-privilege account that has been granted read access to the _internal index within a Search Head Cluster deployment. An attacker satisfying these preconditions can query the _internal index via Splunk's search interface to retrieve the Duo authentication secrets directly (Splunk Advisory).
Successful exploitation allows an authenticated attacker to extract Duo 2FA integration credentials (integrationKey, secretKey, appSecretKey) in plaintext, effectively compromising the two-factor authentication layer protecting Splunk Enterprise. With these secrets, an attacker could bypass MFA controls, potentially enabling account takeover and unauthorized access to Splunk and any systems integrated with the same Duo tenant. The impact is limited to confidentiality — there is no integrity or availability impact — but the downstream risk of 2FA bypass represents a significant escalation path (Splunk Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. Exploitation requires an authenticated user with high privileges (specifically, access to the _internal index), which limits the attack surface considerably. The EPSS score is 0.018% (0.000180), reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Splunk Advisory).
_internal index (e.g., an admin or a custom role with _internal index access)._internal index: Log in to the Splunk web interface or use the Splunk REST API and run a search such as index=_internal integrationKey OR secretKey OR appSecretKey to locate log entries containing Duo 2FA secrets.integrationKey, secretKey, and appSecretKey values from the search results.index=_audit) showing searches against index=_internal containing terms like integrationKey, secretKey, or appSecretKey by non-administrative users._internal index entries containing Duo credential fields (integrationKey, secretKey, appSecretKey) in plaintext — presence of these fields in log data confirms the vulnerable configuration._internal index, particularly during off-hours (Splunk Advisory).Splunk has released patched versions: 9.2.11, 9.3.9, 9.4.7, 10.0.2, and 10.2.0. Organizations should upgrade to one of these versions as the primary remediation. As an interim workaround, restrict access to the _internal index to only essential administrative users by reviewing and tightening role-based access controls, following the principle of least privilege. Additionally, monitor Splunk audit logs for any unauthorized queries against the _internal index and consider rotating Duo integration credentials if unauthorized access is suspected (Splunk Advisory).
Coverage of CVE-2026-20138 has been limited to standard vulnerability aggregation sites and security monitoring platforms. Tenable released a Nessus detection plugin (ID 299407) for the vulnerability shortly after disclosure. No notable researcher commentary or significant social media discussion has been identified beyond routine vulnerability tracking (Tenable Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."