
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20166 is a sensitive information disclosure vulnerability in the Discover Splunk Observability Cloud app for Splunk Enterprise and Splunk Cloud Platform, caused by improper access control. A low-privileged user without the "admin" or "power" Splunk roles can retrieve the Observability Cloud API access token through the app. Affected versions include Splunk Enterprise below 10.2.1 and 10.0.4, and Splunk Cloud Platform below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12. Splunk Enterprise versions below 9.4.9 and 9.3.10 are not affected as the Discover Splunk Observability Cloud app is not bundled with those releases. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Splunk Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), stemming from improper access control within the Discover Splunk Observability Cloud app. A low-privileged, authenticated user can make a network request to retrieve the Observability Cloud API access token that should be restricted to administrative roles. No special conditions or user interaction are required beyond having a valid low-privilege Splunk account and network access to the affected instance. No public proof-of-concept exploit code has been identified at this time (Splunk Advisory).
Successful exploitation allows an attacker to obtain the Observability Cloud API access token, enabling unauthorized access to Observability Cloud resources. This could expose sensitive monitoring data, infrastructure configuration details, and telemetry information. The compromised token may also facilitate lateral movement into connected cloud environments, and an attacker could potentially modify or delete observability data and configurations, impacting both confidentiality and integrity (Splunk Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability requires a valid low-privilege Splunk account and network access, lowering the barrier for insider threats or compromised accounts. The EPSS score is approximately 0.027%, indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Splunk Advisory).
Upgrade to the following patched versions: Splunk Enterprise 10.2.1 or 10.0.4 (and later), or Splunk Cloud Platform 10.2.2510.5, 10.1.2507.16, or 10.0.2503.12 (and later). If immediate upgrading is not possible, restrict access to the Discover Splunk Observability Cloud app using Splunk's role-based access controls to prevent low-privileged users from accessing it. Additionally, monitor Splunk access logs for unauthorized token retrieval attempts as a compensating control (Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."