
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20141 is an improper access control vulnerability in the Splunk Enterprise Monitoring Console App that allows low-privileged, non-admin users to access restricted endpoints, leading to sensitive information disclosure. It affects Splunk Enterprise versions 9.3.0–9.3.8, 9.4.0–9.4.7, and 10.0.0–10.0.2. The Monitoring Console app is bundled with Splunk Enterprise and is not present on Splunk Cloud Platform instances, which are unaffected. The vulnerability was disclosed on February 18, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Splunk Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), stemming from insufficient access control enforcement on Splunk Monitoring Console App endpoints. A low-privileged user — one who does not hold the "admin" Splunk role — can directly access these endpoints over the network without any user interaction, bypassing the intended role-based access controls. No authentication bypass or code execution is involved; the flaw is purely an authorization gap that exposes monitoring data to unauthorized users (Splunk Advisory).
Successful exploitation allows a low-privileged authenticated user to access Splunk Monitoring Console App endpoints that should be restricted to administrators, potentially exposing system performance metrics, deployment topology, indexer cluster health, and other operational intelligence. The confidentiality impact is rated High, while integrity and availability are unaffected. There is no evidence of lateral movement capability directly from this vulnerability, but the exposed operational data could assist an attacker in planning further attacks against the Splunk infrastructure (Splunk Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid low-privileged credentials on an affected Splunk Enterprise instance, limiting the attack surface to authenticated users (Splunk Advisory).
/en-US/app/splunk_monitoring_console/) that are normally restricted to admin users.splunkd_access.log) showing non-admin user accounts making HTTP GET requests to /en-US/app/splunk_monitoring_console/ or related Monitoring Console endpoints./services/server/info, /services/search/jobs initiated from the Monitoring Console context).audit.log) recording access to Monitoring Console views or dashboards by accounts without the admin role.Splunk has released patched versions addressing this vulnerability: upgrade Splunk Enterprise to 9.3.9, 9.4.8, 10.0.2, or 10.0.3 (or later). As a network-level workaround, restrict access to Monitoring Console endpoints using firewall rules or Splunk network access controls to limit reachability to trusted administrative hosts only. Organizations should also audit existing Splunk user roles to ensure the principle of least privilege is enforced and review access logs for any unauthorized access to Monitoring Console functionality (Splunk Advisory).
Coverage of this vulnerability has been limited to automated vulnerability tracking platforms and security aggregators such as VulnDB, CVEFeed, and Tenable (Nessus plugin 299412). A brief technical summary was published by Infinit Security. No significant vendor statements beyond the official Splunk advisory, notable researcher commentary, or broad social media discussion has been observed for this Medium-severity vulnerability (Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."