
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20143 is a Local Privilege Escalation (LPE) and Denial of Service (DoS) vulnerability in Splunk Enterprise for Windows. A low-privileged Windows user who can create a directory on the system drive where Splunk Enterprise is installed can write a malicious Python script into that directory, which may execute with SYSTEM-level privileges upon Splunk service restart. Affected versions are Splunk Enterprise for Windows below 10.2.0, 10.0.3, 9.4.8, and 9.3.9. The vulnerability was disclosed on February 18, 2026, with a CVSS v3.1 base score of 7.7 (High) (Splunk Advisory).
The root cause is an insecure Python module search path (CWE-427: Uncontrolled Search Path Element), where Splunk Enterprise on Windows resolves Python modules from directories that a low-privileged user can create and write to on the system drive. An attacker exploits this by creating a specially named directory on the system drive and placing a malicious Python script there that mimics a legitimate module. When the Splunk Enterprise service restarts, it may load the attacker-controlled script with SYSTEM-level privileges. Exploitation requires user interaction (e.g., a service restart) and high attack complexity, but no prior privileges are needed (Splunk Advisory).
Successful exploitation grants the attacker SYSTEM-level code execution on the affected Windows host, resulting in full confidentiality, integrity, and availability compromise. This enables the attacker to read sensitive Splunk data (including indexed logs and credentials), modify system configurations, and cause a Denial of Service by disrupting the Splunk Enterprise instance. The changed scope indicates impact can extend beyond the Splunk process itself to the underlying operating system (Splunk Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The vulnerability requires local access, user interaction (a service restart), and high attack complexity, limiting opportunistic exploitation. The CVE status is listed as Reserved, and it is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Detection is available via Tenable Nessus plugin 299605 (Tenable, Splunk Advisory).
C:\) and identify a directory path that Splunk's Python interpreter includes in its module search path and that a low-privileged user can create..py) in non-standard directories on the system drive (e.g., C:\) that match names of Python standard library modules; newly created directories on the system drive writable by non-administrative users.splunkd.exe) running as SYSTEM, such as cmd.exe, powershell.exe, net.exe, or network utilities.splunkd.log) referencing unexpected Python module load paths.Splunk has released patched versions addressing this vulnerability: 10.2.0, 10.0.3, 9.4.8, and 9.3.9 for Splunk Enterprise on Windows. Organizations should upgrade to one of these versions as the primary remediation. As a workaround, restrict the ability of low-privileged users to create directories on the system drive (e.g., via Windows filesystem ACLs), and ensure Splunk is installed on a drive/path where directory creation by non-administrators is not permitted (Splunk Advisory).
Security news outlet SecurityOnline.info covered the vulnerability shortly after disclosure, noting that the flaw exposes Windows Splunk servers to system takeover (SecurityOnline). The Egyptian Financial CERT (EG-FinCIRT) issued a security update advisory referencing the vulnerability (EG-FinCIRT). Overall community reaction has been moderate given the local-only attack vector and requirement for user interaction.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."