CVE-2026-20138
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20138 is a sensitive information disclosure vulnerability in Splunk Enterprise affecting Search Head Cluster (SHC) deployments. In affected versions, a user with a role granting access to the Splunk _internal index can view the integrationKey, secretKey, and appSecretKey secrets generated by the Duo Two-Factor Authentication for Splunk Enterprise integration in plain text. The vulnerability affects Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11. It was disclosed on February 18, 2026, and carries a CVSS v3.1 base score of 4.9 (Medium) (Splunk Advisory).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File), meaning Splunk Enterprise improperly writes Duo 2FA secrets — specifically integrationKey, secretKey, and appSecretKey — into the _internal index in plaintext rather than masking or encrypting them. Exploitation requires network access and a high-privilege account that has been granted read access to the _internal index within a Search Head Cluster deployment. An attacker satisfying these preconditions can query the _internal index via Splunk's search interface to retrieve the Duo authentication secrets directly (Splunk Advisory).

Impact

Successful exploitation allows an authenticated attacker to extract Duo 2FA integration credentials (integrationKey, secretKey, appSecretKey) in plaintext, effectively compromising the two-factor authentication layer protecting Splunk Enterprise. With these secrets, an attacker could bypass MFA controls, potentially enabling account takeover and unauthorized access to Splunk and any systems integrated with the same Duo tenant. The impact is limited to confidentiality — there is no integrity or availability impact — but the downstream risk of 2FA bypass represents a significant escalation path (Splunk Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. Exploitation requires an authenticated user with high privileges (specifically, access to the _internal index), which limits the attack surface considerably. The EPSS score is 0.018% (0.000180), reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Splunk Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Splunk Enterprise Search Head Cluster deployment running a vulnerable version (below 10.2.0, 10.0.2, 9.4.7, 9.3.9, or 9.2.11) with Duo Two-Factor Authentication for Splunk Enterprise configured.
  2. Obtain privileged credentials: Acquire credentials for a Splunk user account that has a role granting read access to the _internal index (e.g., an admin or a custom role with _internal index access).
  3. Query the _internal index: Log in to the Splunk web interface or use the Splunk REST API and run a search such as index=_internal integrationKey OR secretKey OR appSecretKey to locate log entries containing Duo 2FA secrets.
  4. Extract secrets: Retrieve the plaintext integrationKey, secretKey, and appSecretKey values from the search results.
  5. Abuse Duo credentials: Use the extracted secrets to interact with the Duo API, potentially bypassing or manipulating 2FA controls for Splunk users or other integrated services (Splunk Advisory).

Indicators of compromise

  • Logs: Splunk audit logs (index=_audit) showing searches against index=_internal containing terms like integrationKey, secretKey, or appSecretKey by non-administrative users.
  • Logs: Splunk _internal index entries containing Duo credential fields (integrationKey, secretKey, appSecretKey) in plaintext — presence of these fields in log data confirms the vulnerable configuration.
  • Network: Unexpected or anomalous API calls to Duo's API endpoints originating from unfamiliar IP addresses, which may indicate extracted credentials are being used.
  • Process/Behavior: Unusual search activity from accounts that do not typically query the _internal index, particularly during off-hours (Splunk Advisory).

Mitigation and workarounds

Splunk has released patched versions: 9.2.11, 9.3.9, 9.4.7, 10.0.2, and 10.2.0. Organizations should upgrade to one of these versions as the primary remediation. As an interim workaround, restrict access to the _internal index to only essential administrative users by reviewing and tightening role-based access controls, following the principle of least privilege. Additionally, monitor Splunk audit logs for any unauthorized queries against the _internal index and consider rotating Duo integration credentials if unauthorized access is suspected (Splunk Advisory).

Community reactions

Coverage of CVE-2026-20138 has been limited to standard vulnerability aggregation sites and security monitoring platforms. Tenable released a Nessus detection plugin (ID 299407) for the vulnerability shortly after disclosure. No notable researcher commentary or significant social media discussion has been identified beyond routine vulnerability tracking (Tenable Plugin).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management