CVE-2026-20166
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20166 is a sensitive information disclosure vulnerability in the Discover Splunk Observability Cloud app for Splunk Enterprise and Splunk Cloud Platform, caused by improper access control. A low-privileged user without the "admin" or "power" Splunk roles can retrieve the Observability Cloud API access token through the app. Affected versions include Splunk Enterprise below 10.2.1 and 10.0.4, and Splunk Cloud Platform below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12. Splunk Enterprise versions below 9.4.9 and 9.3.10 are not affected as the Discover Splunk Observability Cloud app is not bundled with those releases. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Splunk Advisory).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), stemming from improper access control within the Discover Splunk Observability Cloud app. A low-privileged, authenticated user can make a network request to retrieve the Observability Cloud API access token that should be restricted to administrative roles. No special conditions or user interaction are required beyond having a valid low-privilege Splunk account and network access to the affected instance. No public proof-of-concept exploit code has been identified at this time (Splunk Advisory).

Impact

Successful exploitation allows an attacker to obtain the Observability Cloud API access token, enabling unauthorized access to Observability Cloud resources. This could expose sensitive monitoring data, infrastructure configuration details, and telemetry information. The compromised token may also facilitate lateral movement into connected cloud environments, and an attacker could potentially modify or delete observability data and configurations, impacting both confidentiality and integrity (Splunk Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability requires a valid low-privilege Splunk account and network access, lowering the barrier for insider threats or compromised accounts. The EPSS score is approximately 0.027%, indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Splunk Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Splunk Enterprise (10.0.x or 10.2.x) or Splunk Cloud Platform instance with the Discover Splunk Observability Cloud app installed and accessible over the network.
  2. Obtain low-privilege credentials: Acquire or use any valid Splunk account that does not hold the "admin" or "power" role — this could be a standard user account.
  3. Authenticate to Splunk: Log in to the Splunk web interface or API using the low-privilege credentials.
  4. Access the vulnerable app endpoint: Navigate to or send an authenticated HTTP request to the Discover Splunk Observability Cloud app's endpoint that exposes the Observability Cloud API access token due to missing access control checks.
  5. Retrieve the API token: Extract the Observability Cloud API access token from the app's response.
  6. Leverage the token: Use the retrieved API token to authenticate against Splunk Observability Cloud APIs, access sensitive monitoring data, modify configurations, or attempt lateral movement into connected cloud environments (Splunk Advisory).

Indicators of compromise

  • Logs: Splunk internal audit logs showing low-privileged users accessing the Discover Splunk Observability Cloud app endpoints, particularly token retrieval endpoints, outside of normal administrative activity.
  • Logs: Unexpected or anomalous API calls to Splunk Observability Cloud APIs using tokens associated with non-admin Splunk accounts.
  • Network: Outbound API requests to Splunk Observability Cloud infrastructure originating from user sessions not associated with admin or power roles.
  • Behavioral: Low-privileged Splunk user accounts querying app configuration or token endpoints that are not part of their normal workflow.

Mitigation and workarounds

Upgrade to the following patched versions: Splunk Enterprise 10.2.1 or 10.0.4 (and later), or Splunk Cloud Platform 10.2.2510.5, 10.1.2507.16, or 10.0.2503.12 (and later). If immediate upgrading is not possible, restrict access to the Discover Splunk Observability Cloud app using Splunk's role-based access controls to prevent low-privileged users from accessing it. Additionally, monitor Splunk access logs for unauthorized token retrieval attempts as a compensating control (Splunk Advisory).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management