
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20259 is an improper access control vulnerability in Splunk Enterprise and Splunk Cloud Platform that allows a privileged user with the edit_saved_search_owner capability to reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks sufficient access control enforcement. Affected versions include Splunk Enterprise below 10.2.4 and 10.0.7, and Splunk Cloud Platform below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131. Disclosed on June 10, 2026, it carries a CVSS v3.1 base score of 5.5 (Medium) (Splunk Advisory, GitHub Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control). The root cause is that the saved search ownership reassignment API endpoint does not enforce proper authorization checks, allowing a user holding the high-privilege edit_saved_search_owner capability to reassign ownership of saved searches to arbitrary users beyond their permitted scope. Exploitation requires network access and a Splunk account with the edit_saved_search_owner capability, but no user interaction is needed. No public proof-of-concept code has been identified (Splunk Advisory, GitHub Advisory).
Successful exploitation allows an attacker with the edit_saved_search_owner capability to grant unauthorized users access to sensitive saved searches and the underlying data those searches expose, resulting in a high confidentiality impact and low integrity impact with no availability impact. This could enable unauthorized disclosure of sensitive log data, security alerts, or business intelligence stored within Splunk, and may facilitate privilege escalation or lateral data access within the platform. Availability is not affected by this vulnerability (Splunk Advisory, GitHub Advisory).
edit_saved_search_owner capability (e.g., through credential theft, phishing, or insider access)._audit index) showing unexpected edit_saved_search_owner actions, particularly ownership changes to users not previously associated with those searches or outside expected administrative accounts.Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 10.2.4 and 10.0.7; Splunk Cloud Platform 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131. As a workaround, restrict the edit_saved_search_owner capability to only trusted administrators and audit existing role assignments to remove it from unnecessary accounts. Regularly review saved search ownership changes to detect unauthorized reassignments (Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."