
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20144 is a sensitive information disclosure vulnerability in Splunk Enterprise and Splunk Cloud Platform affecting Search Head Cluster (SHC) deployments. A privileged user with a role granting access to the _internal index can view SAML configurations — including credentials for Attribute Query Requests (AQRs) or Authentication extensions — in plain text within the conf.log file. Affected Splunk Enterprise versions are below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11; affected Splunk Cloud Platform versions are below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120. It carries a CVSS v3.1 base score of 4.9 (Medium) (Splunk Advisory).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File). When SAML features such as Attribute Query Requests or Authentication extensions are configured in a Search Head Cluster deployment, Splunk logs the associated configuration — including sensitive credentials — in plain text to the conf.log file within the _internal index. An attacker exploiting this vulnerability must already hold a privileged role with read access to the _internal index, making the attack vector network-accessible but requiring high privileges and no user interaction (Splunk Advisory).
Successful exploitation allows a privileged user to read SAML authentication secrets and configuration details — such as AQR credentials or authentication extension parameters — in plain text from log files. This exposure could enable unauthorized access to systems integrated via SAML, facilitate authentication bypass, or allow lateral movement into federated identity environments. The confidentiality impact is rated High, with no integrity or availability impact (Splunk Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated user with high privileges (access to the _internal index), significantly limiting the attack surface (Splunk Advisory).
_internal index._internal index: Execute a Splunk search query such as index=_internal source=*conf.log* SAML to locate log entries containing SAML configuration data.conf.log entries for plain-text SAML credentials, including AQR secrets or authentication extension parameters.index=_internal with filters for conf.log or SAML-related terms by users who do not normally query internal indexes.conf.log entries within the _internal index, particularly from non-administrative accounts._internal index access events._internal index access performing bulk or automated searches against conf.log outside of normal operational hours (Splunk Advisory).Splunk has released patched versions addressing this vulnerability. Organizations should upgrade Splunk Enterprise to version 10.2.0, 10.0.2, 9.4.7, 9.3.8, or 9.2.11 (or later within each release line), and Splunk Cloud Platform to 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, or 9.3.2411.120 (or later). As an interim workaround, restrict access to the _internal index to only users who operationally require it, and audit existing role assignments to remove unnecessary access. Additionally, monitor conf.log for unauthorized access attempts and review SAML configuration secrets for potential rotation if exposure is suspected (Splunk Advisory).
Coverage of this vulnerability has been limited to standard security aggregation sites and automated feeds, with no notable researcher commentary or significant social media discussion identified. The EG-FinCIRT published a brief security update referencing the Splunk February 2026 advisories (EG-FinCIRT). Tenable added detection support via Nessus plugin 299408 (Tenable).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."