
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20204 is a Remote Code Execution (RCE) vulnerability in Splunk Enterprise and Splunk Cloud Platform caused by improper handling and insufficient isolation of temporary files in the apptemp directory. A low-privileged user without admin or power Splunk roles can exploit this flaw by uploading a malicious file to $SPLUNK_HOME/var/run/splunk/apptemp. Affected Splunk Enterprise versions include those below 10.2.1, 10.0.5, 9.4.10, and 9.3.11; affected Splunk Cloud Platform versions include those below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127. Disclosed on April 15, 2026, it carries a CVSS v3.1 base score of 7.1 (High) (Splunk Advisory, GitHub Advisory).
The root cause is classified as CWE-377 (Insecure Temporary File), where the apptemp directory ($SPLUNK_HOME/var/run/splunk/apptemp) lacks proper access controls and file isolation, allowing low-privileged users to write and potentially execute malicious files. The attack vector is network-based with high attack complexity, requiring low privileges and user interaction to trigger execution of the uploaded payload. The associated CAPEC pattern is CAPEC-155 (Screen Temporary Files for Sensitive Information), indicating that the temporary file handling mechanism can be abused to stage and execute malicious code (Splunk Advisory, GitHub Advisory). No public proof-of-concept code has been identified at this time.
Successful exploitation allows a low-privileged attacker to achieve full remote code execution on affected Splunk instances, resulting in high confidentiality, integrity, and availability impact. An attacker could access sensitive log data and credentials stored within Splunk, modify or destroy indexed data, and disrupt Splunk's availability as a security monitoring platform. Given Splunk's role as a central SIEM and log aggregation platform in many enterprises, compromise could facilitate lateral movement, blind defenders to ongoing attacks, and expose sensitive organizational data (Splunk Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.18–0.21%, placing it in the 44th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).
admin or power role — this could be through phishing, credential stuffing, or use of a legitimately provisioned low-privilege account.$SPLUNK_HOME/var/run/splunk/apptemp directory, exploiting the lack of isolation controls in that directory.apptemp directory.$SPLUNK_HOME/var/run/splunk/apptemp; files in apptemp with unusual extensions (.sh, .py, .exe, .ps1) or recently modified timestamps not associated with legitimate Splunk operations.splunkd.log) showing file write operations to the apptemp directory by low-privileged user accounts; audit logs recording unexpected file upload API calls from non-admin users.splunkd) such as shells (/bin/bash, cmd.exe), network utilities (curl, wget, nc), or scripting engines (python, powershell) not associated with normal Splunk operations.Splunk has released patched versions addressing this vulnerability. For Splunk Enterprise, upgrade to version 10.2.1, 10.0.5, 9.4.10, or 9.3.11 (or later). For Splunk Cloud Platform, upgrade to 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, or 9.3.2411.127 (or later). As interim mitigations, restrict file upload capabilities to the apptemp directory, enforce strict access controls limiting which users can write to that path, and monitor the directory for suspicious file creation or execution activity (Splunk Advisory, GitHub Advisory).
The vulnerability received coverage from several cybersecurity news outlets including GBHackers, CyberSecurityNews, and IT Security News, highlighting the risk of RCE by low-privileged users in a widely deployed security platform. The Hacker News included it in their weekly recap for the week of April 20, 2026. Check Point Research also referenced it in their April 20, 2026 threat intelligence report. Community sentiment on social media (Mastodon, Bluesky) reflected concern given Splunk's central role in enterprise security operations, though the lack of a public PoC tempered urgency (GBHackers, The Hacker News, Check Point).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."