CVE-2026-20143
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20143 is a Local Privilege Escalation (LPE) and Denial of Service (DoS) vulnerability in Splunk Enterprise for Windows. A low-privileged Windows user who can create a directory on the system drive where Splunk Enterprise is installed can write a malicious Python script into that directory, which may execute with SYSTEM-level privileges upon Splunk service restart. Affected versions are Splunk Enterprise for Windows below 10.2.0, 10.0.3, 9.4.8, and 9.3.9. The vulnerability was disclosed on February 18, 2026, with a CVSS v3.1 base score of 7.7 (High) (Splunk Advisory).

Technical details

The root cause is an insecure Python module search path (CWE-427: Uncontrolled Search Path Element), where Splunk Enterprise on Windows resolves Python modules from directories that a low-privileged user can create and write to on the system drive. An attacker exploits this by creating a specially named directory on the system drive and placing a malicious Python script there that mimics a legitimate module. When the Splunk Enterprise service restarts, it may load the attacker-controlled script with SYSTEM-level privileges. Exploitation requires user interaction (e.g., a service restart) and high attack complexity, but no prior privileges are needed (Splunk Advisory).

Impact

Successful exploitation grants the attacker SYSTEM-level code execution on the affected Windows host, resulting in full confidentiality, integrity, and availability compromise. This enables the attacker to read sensitive Splunk data (including indexed logs and credentials), modify system configurations, and cause a Denial of Service by disrupting the Splunk Enterprise instance. The changed scope indicates impact can extend beyond the Splunk process itself to the underlying operating system (Splunk Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The vulnerability requires local access, user interaction (a service restart), and high attack complexity, limiting opportunistic exploitation. The CVE status is listed as Reserved, and it is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Detection is available via Tenable Nessus plugin 299605 (Tenable, Splunk Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Windows system running a vulnerable version of Splunk Enterprise (below 10.2.0, 10.0.3, 9.4.8, or 9.3.9) and confirm the attacker has a low-privileged local Windows account.
  2. Identify writable path: Determine the system drive (typically C:\) and identify a directory path that Splunk's Python interpreter includes in its module search path and that a low-privileged user can create.
  3. Create malicious directory: Using the low-privileged account, create the target directory on the system drive (e.g., a path that Splunk's Python resolves before legitimate module locations).
  4. Plant malicious Python script: Write a malicious Python script into the created directory, named to match a Python module that Splunk loads at startup (e.g., a standard library module name).
  5. Trigger service restart: Wait for or induce a Splunk Enterprise service restart (e.g., through a scheduled restart, system reboot, or by triggering a crash/DoS condition).
  6. Achieve SYSTEM execution: Upon restart, Splunk's Python interpreter loads the attacker-controlled script with SYSTEM-level privileges, executing arbitrary commands such as adding a backdoor user, establishing persistence, or exfiltrating data (Splunk Advisory).

Indicators of compromise

  • File System: Unexpected Python script files (.py) in non-standard directories on the system drive (e.g., C:\) that match names of Python standard library modules; newly created directories on the system drive writable by non-administrative users.
  • Process: Unusual child processes spawned by the Splunk service (splunkd.exe) running as SYSTEM, such as cmd.exe, powershell.exe, net.exe, or network utilities.
  • Logs: Windows Event Logs showing new directory creation on the system drive by low-privileged accounts (Event ID 4663); Splunk internal logs (splunkd.log) referencing unexpected Python module load paths.
  • Registry/Persistence: New scheduled tasks, services, or registry run keys created by the SYSTEM account following a Splunk service restart.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability: 10.2.0, 10.0.3, 9.4.8, and 9.3.9 for Splunk Enterprise on Windows. Organizations should upgrade to one of these versions as the primary remediation. As a workaround, restrict the ability of low-privileged users to create directories on the system drive (e.g., via Windows filesystem ACLs), and ensure Splunk is installed on a drive/path where directory creation by non-administrators is not permitted (Splunk Advisory).

Community reactions

Security news outlet SecurityOnline.info covered the vulnerability shortly after disclosure, noting that the flaw exposes Windows Splunk servers to system takeover (SecurityOnline). The Egyptian Financial CERT (EG-FinCIRT) issued a security update advisory referencing the vulnerability (EG-FinCIRT). Overall community reaction has been moderate given the local-only attack vector and requirement for user interaction.

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management