CVE-2026-20164
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20164 is an improper access control vulnerability in Splunk Enterprise and Splunk Cloud Platform that allows low-privileged users to access a sensitive REST API endpoint and retrieve stored credentials. Specifically, users without the "admin" or "power" Splunk roles can query the /splunkd/__raw/servicesNS/-/-/configs/conf-passwords endpoint, exposing hashed or plaintext password values from the passwords.conf configuration file. Affected Splunk Enterprise versions include 9.3.x before 9.3.10, 9.4.x before 9.4.9, 10.0.x before 10.0.3, and below 10.2.0; affected Splunk Cloud Platform versions include those below 10.2.2510.5, 10.1.2507.16, 10.0.2503.11, and 9.3.2411.123. The vulnerability was published on March 11, 2026, with a patch advisory released the same day. It carries a CVSS v3.1 base score of 6.5 (Medium) (Splunk Advisory).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), stemming from insufficient access control enforcement on the /splunkd/__raw/servicesNS/-/-/configs/conf-passwords REST API endpoint. A low-privileged authenticated user — one who does not hold the "admin" or "power" Splunk roles — can send a direct HTTP GET request to this endpoint and receive credential data stored in passwords.conf, which may include both hashed and plaintext passwords. The attack vector is network-based, requires low privileges (any valid Splunk account), no user interaction, and low attack complexity, making it straightforward to exploit once an attacker has any foothold in the Splunk environment (Splunk Advisory, Tenable).

Impact

Successful exploitation results in unauthorized disclosure of sensitive credentials stored in Splunk's passwords.conf file, which may include integration credentials, service account passwords, and API keys used by Splunk apps and add-ons. This is a confidentiality-only impact with no direct effect on integrity or availability, but the exposed credentials could enable lateral movement to other systems, services, or cloud environments that rely on those stored secrets. In environments where Splunk integrates with critical infrastructure (e.g., SIEM data sources, cloud platforms, databases), credential exposure could have significant downstream consequences (Splunk Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of this report. The vulnerability requires a valid (low-privileged) Splunk account, which limits opportunistic exploitation but makes it a meaningful insider threat or post-compromise escalation vector. The EPSS score is approximately 0.031% (0.000310), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It is detectable via Nessus plugin 301873 (Tenable, Splunk Advisory).

Exploitation steps

  1. Obtain low-privileged credentials: Acquire any valid Splunk user account that does not hold the "admin" or "power" role — this could be through phishing, credential stuffing, or insider access.
  2. Authenticate to Splunk: Log in to the target Splunk instance using the low-privileged account to obtain a valid session token or use HTTP Basic Authentication.
  3. Query the vulnerable endpoint: Send an authenticated HTTP GET request to the exposed REST API endpoint:
    GET /splunkd/__raw/servicesNS/-/-/configs/conf-passwords
    Authorization: Basic <base64-encoded-credentials>
  4. Retrieve credential data: Parse the API response, which returns the contents of passwords.conf, potentially including hashed or plaintext passwords for Splunk apps, add-ons, and integrations.
  5. Leverage exposed credentials: Use the retrieved credentials to authenticate to downstream systems, services, or cloud platforms integrated with Splunk, enabling lateral movement or further compromise (Splunk Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP GET requests to /splunkd/__raw/servicesNS/-/-/configs/conf-passwords from non-administrative user accounts; requests originating from unexpected IP addresses or outside normal business hours.
  • Logs: Splunk internal audit logs (_audit index) showing access to the conf-passwords REST endpoint by users without "admin" or "power" roles; splunkd_access.log entries for the above endpoint path from low-privileged accounts.
  • Behavioral: A low-privileged Splunk user account making API calls to configuration endpoints that are not typical for their role; bulk or scripted queries to the REST API from a single account in a short time window.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 9.3.10, 9.4.9, 10.0.3, and 10.2.0; Splunk Cloud Platform 9.3.2411.123, 10.0.2503.11, 10.1.2507.16, and 10.2.2510.5. Organizations should upgrade to the applicable fixed version as the primary remediation. As an interim measure, administrators should audit Splunk user accounts and ensure that only trusted users with legitimate need are granted any level of access, and consider restricting network access to the Splunk REST API to authorized hosts only (Splunk Advisory).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management