CVE-2026-20142
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20142 is a sensitive information disclosure vulnerability in Splunk Enterprise affecting Search Head Cluster (SHC) deployments. A user holding a role with access to the Splunk _internal index can view the RSA accessKey value from the Authentication.conf configuration file in plain text. The vulnerability affects Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11. It was disclosed on February 18, 2026, and carries a CVSS v3.1 base score of 4.9 (Medium) (Splunk Advisory).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File), where Splunk Enterprise logs RSA accessKey credentials from the Authentication.conf file into the _internal index without proper sanitization or masking. An authenticated attacker with a role that grants read access to the _internal index in a Search Head Cluster deployment can query this index and retrieve the RSA accessKey in plain text. Exploitation requires network access and a high-privilege role (specifically, _internal index access), limiting the attack surface but not eliminating the risk in environments with broad role assignments (Splunk Advisory).

Impact

Successful exploitation allows a privileged user to obtain RSA accessKey credentials in plain text, which could be leveraged to compromise RSA-based authentication systems integrated with Splunk. The confidentiality impact is high — exposed credentials could enable unauthorized access to downstream authentication infrastructure — while integrity and availability are not directly affected by this vulnerability. In environments where RSA authentication is broadly used, credential exposure could facilitate lateral movement or privilege escalation beyond the Splunk platform (Splunk Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the disclosure date (Splunk Advisory). The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for a high-privilege role with _internal index access, reducing the likelihood of opportunistic attacks.

Exploitation steps

  1. Identify target: Confirm the target Splunk Enterprise deployment is a Search Head Cluster (SHC) running a vulnerable version (below 10.2.0, 10.0.2, 9.4.7, 9.3.9, or 9.2.11).
  2. Obtain privileged access: Authenticate to Splunk with a user account that holds a role granting read access to the _internal index (e.g., admin or a custom role with _internal index permissions).
  3. Query the _internal index: Execute a Splunk search such as index=_internal accessKey or index=_internal Authentication.conf to surface log entries containing the RSA accessKey value.
  4. Extract credentials: Review the search results to obtain the RSA accessKey in plain text as logged from the Authentication.conf configuration file.
  5. Leverage credentials: Use the extracted RSA accessKey to authenticate against RSA-integrated systems or further compromise authentication infrastructure (Splunk Advisory).

Indicators of compromise

  • Logs: Splunk search audit logs (_audit index) showing queries against index=_internal with terms like accessKey, Authentication.conf, or RSA by non-administrative or unexpected user accounts.
  • Logs: Splunk _internal index entries containing RSA accessKey values in plain text, indicating the vulnerable logging behavior is present.
  • Network: Unusual authentication attempts to RSA-integrated systems originating from unexpected sources following access to the Splunk _internal index.
  • Process/Behavior: Unexpected or anomalous role assignments granting _internal index access to non-administrative users in Splunk role configurations.

Mitigation and workarounds

Splunk has released patched versions: 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11. Organizations should upgrade to one of these versions as the primary remediation. As an interim workaround, restrict access to the _internal index to only users who strictly require it, and audit all roles with _internal index permissions to identify potential credential exposure. Additionally, rotate any RSA accessKey values that may have been exposed in affected deployments (Splunk Advisory).

Community reactions

Coverage of CVE-2026-20142 has been limited to automated vulnerability tracking platforms and security aggregators such as VulnDB, CVEfeed, and Vulners, with no notable researcher commentary or significant social media discussion identified. A brief write-up was published by Infinit Security shortly after disclosure (Splunk Advisory). The Egyptian Financial Institutions CIRT (EGFINCIRT) issued a Splunk security update notice referencing this CVE in February 2026.

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management