CVE-2026-20259
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20259 is an improper access control vulnerability in Splunk Enterprise and Splunk Cloud Platform that allows a privileged user with the edit_saved_search_owner capability to reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks sufficient access control enforcement. Affected versions include Splunk Enterprise below 10.2.4 and 10.0.7, and Splunk Cloud Platform below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131. Disclosed on June 10, 2026, it carries a CVSS v3.1 base score of 5.5 (Medium) (Splunk Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control). The root cause is that the saved search ownership reassignment API endpoint does not enforce proper authorization checks, allowing a user holding the high-privilege edit_saved_search_owner capability to reassign ownership of saved searches to arbitrary users beyond their permitted scope. Exploitation requires network access and a Splunk account with the edit_saved_search_owner capability, but no user interaction is needed. No public proof-of-concept code has been identified (Splunk Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker with the edit_saved_search_owner capability to grant unauthorized users access to sensitive saved searches and the underlying data those searches expose, resulting in a high confidentiality impact and low integrity impact with no availability impact. This could enable unauthorized disclosure of sensitive log data, security alerts, or business intelligence stored within Splunk, and may facilitate privilege escalation or lateral data access within the platform. Availability is not affected by this vulnerability (Splunk Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Splunk Enterprise or Splunk Cloud Platform instance running a vulnerable version (Enterprise < 10.2.4 or < 10.0.7; Cloud Platform < respective patched versions).
  2. Obtain privileged credentials: Acquire credentials for a Splunk account that holds a role with the edit_saved_search_owner capability (e.g., through credential theft, phishing, or insider access).
  3. Identify target saved searches: Enumerate saved searches within the Splunk environment that contain sensitive data or queries of interest.
  4. Craft ownership reassignment request: Send an authenticated API request to the saved search ownership reassignment endpoint, specifying a target user outside the attacker's authorized scope as the new owner.
  5. Unauthorized access granted: The target user (or attacker-controlled account) now has ownership of the reassigned saved search, gaining access to its contents and any sensitive data it exposes (Splunk Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Splunk audit logs (_audit index) showing unexpected edit_saved_search_owner actions, particularly ownership changes to users not previously associated with those searches or outside expected administrative accounts.
  • Logs: API access logs recording calls to the saved search ownership reassignment endpoint from unusual source IPs or at unusual times.
  • Behavioral: Saved searches with recently changed ownership that do not align with normal administrative activity or change management records.
  • Behavioral: Users accessing saved searches they did not previously own or create, especially searches containing sensitive data sources.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 10.2.4 and 10.0.7; Splunk Cloud Platform 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131. As a workaround, restrict the edit_saved_search_owner capability to only trusted administrators and audit existing role assignments to remove it from unnecessary accounts. Regularly review saved search ownership changes to detect unauthorized reassignments (Splunk Advisory).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20296HIGH8.3
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20297HIGH7.2
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20298MEDIUM6.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20259MEDIUM5.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026
CVE-2026-20258MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management