CVE-2026-20144
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20144 is a sensitive information disclosure vulnerability in Splunk Enterprise and Splunk Cloud Platform affecting Search Head Cluster (SHC) deployments. A privileged user with a role granting access to the _internal index can view SAML configurations — including credentials for Attribute Query Requests (AQRs) or Authentication extensions — in plain text within the conf.log file. Affected Splunk Enterprise versions are below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11; affected Splunk Cloud Platform versions are below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120. It carries a CVSS v3.1 base score of 4.9 (Medium) (Splunk Advisory).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File). When SAML features such as Attribute Query Requests or Authentication extensions are configured in a Search Head Cluster deployment, Splunk logs the associated configuration — including sensitive credentials — in plain text to the conf.log file within the _internal index. An attacker exploiting this vulnerability must already hold a privileged role with read access to the _internal index, making the attack vector network-accessible but requiring high privileges and no user interaction (Splunk Advisory).

Impact

Successful exploitation allows a privileged user to read SAML authentication secrets and configuration details — such as AQR credentials or authentication extension parameters — in plain text from log files. This exposure could enable unauthorized access to systems integrated via SAML, facilitate authentication bypass, or allow lateral movement into federated identity environments. The confidentiality impact is rated High, with no integrity or availability impact (Splunk Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated user with high privileges (access to the _internal index), significantly limiting the attack surface (Splunk Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Splunk Search Head Cluster deployment running a vulnerable version of Splunk Enterprise or Splunk Cloud Platform with SAML AQR or Authentication extensions configured.
  2. Authenticate with privileged account: Log in to Splunk using credentials for an account that holds a role with read access to the _internal index.
  3. Search the _internal index: Execute a Splunk search query such as index=_internal source=*conf.log* SAML to locate log entries containing SAML configuration data.
  4. Extract credentials: Review the returned conf.log entries for plain-text SAML credentials, including AQR secrets or authentication extension parameters.
  5. Leverage exposed secrets: Use the extracted SAML credentials to attempt unauthorized access to systems integrated via SAML federation or to craft authentication bypass attempts (Splunk Advisory).

Indicators of compromise

  • Logs: Splunk audit logs showing searches against index=_internal with filters for conf.log or SAML-related terms by users who do not normally query internal indexes.
  • Logs: Unusual or repeated access to conf.log entries within the _internal index, particularly from non-administrative accounts.
  • Network: Authentication attempts to SAML-integrated services originating from unexpected IP addresses or user agents shortly after _internal index access events.
  • Process/Behavior: User accounts with _internal index access performing bulk or automated searches against conf.log outside of normal operational hours (Splunk Advisory).

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability. Organizations should upgrade Splunk Enterprise to version 10.2.0, 10.0.2, 9.4.7, 9.3.8, or 9.2.11 (or later within each release line), and Splunk Cloud Platform to 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, or 9.3.2411.120 (or later). As an interim workaround, restrict access to the _internal index to only users who operationally require it, and audit existing role assignments to remove unnecessary access. Additionally, monitor conf.log for unauthorized access attempts and review SAML configuration secrets for potential rotation if exposure is suspected (Splunk Advisory).

Community reactions

Coverage of this vulnerability has been limited to standard security aggregation sites and automated feeds, with no notable researcher commentary or significant social media discussion identified. The EG-FinCIRT published a brief security update referencing the Splunk February 2026 advisories (EG-FinCIRT). Tenable added detection support via Nessus plugin 299408 (Tenable).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20296HIGH8.3
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20297HIGH7.2
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20298MEDIUM6.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20259MEDIUM5.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026
CVE-2026-20258MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management