
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20296 is a Cross-Site Request Forgery (CSRF) combined with SPL injection vulnerability in Splunk's Deployment Server component that allows unauthenticated attackers to trick privileged users into executing arbitrary Search Processing Language (SPL) searches as splunk-system-user. It affects Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24. The vulnerability was published on July 15, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.3 (High) (Splunk Advisory, GitHub Advisory).
The root cause is a dual weakness: Deployment Server endpoints in Splunk Web fail to validate CSRF tokens on GET requests (CWE-352), and caller-supplied input is not properly neutralized before being incorporated into SPL searches. An attacker crafts a malicious link or page that, when visited by a user holding the list_deployment_server capability, silently triggers a GET request to a vulnerable Deployment Server endpoint with attacker-controlled SPL content. Because no CSRF token validation occurs on these GET requests, the search executes in the context of splunk-system-user, a highly privileged internal account. This chained CSRF-plus-injection attack requires no privileges from the attacker but does require user interaction from a specifically privileged victim (Splunk Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary SPL searches as splunk-system-user, granting access to stored credentials (such as those configured in Splunk inputs and outputs) and all indexed data within the Splunk environment. The high confidentiality and integrity impacts mean sensitive log data, security events, and credentials stored in Splunk could be exfiltrated or manipulated. The availability impact is rated low, indicating the primary risk is data exposure and potential credential theft that could enable lateral movement into other systems (Splunk Advisory, GitHub Advisory).
list_deployment_server capability (e.g., administrators or deployment managers).| inputlookup or credential-extracting SPL commands).splunk-system-user privileges, potentially returning stored credentials, sensitive indexed data, or configuration details to an attacker-controlled destination (e.g., via | sendemail or exfiltration SPL commands) (Splunk Advisory, GitHub Advisory)._audit index) showing SPL searches executed by splunk-system-user that were not initiated through normal administrative workflows, particularly searches involving credential stores, inputlookup, rest, or data exfiltration commands./en-US/app/ or /services/deployment/) with unusual or encoded query parameters from authenticated user sessions.| sendemail, | outputlookup to remote paths, or HTTP-based SPL commands._internal logs showing searches run as splunk-system-user with anomalous search strings or at unusual times inconsistent with scheduled searches.Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 10.4.1, 10.2.5, 10.0.8, and 9.4.13; Splunk Cloud Platform 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24. Upgrading to a patched version is the primary recommended remediation. As an interim measure, organizations should restrict the list_deployment_server capability to the minimum number of users necessary and train those users to be vigilant about clicking links from untrusted sources while authenticated to Splunk. Additionally, implementing network-level controls to limit access to Splunk Web from untrusted networks can reduce the attack surface (Splunk Advisory, GitHub Advisory).
The vulnerability received coverage from multiple security news outlets including SecurityWeek, GBHackers, CyberSecurityNews, and SecurityOnline shortly after disclosure on July 15, 2026, with articles highlighting the credential exposure risk (SecurityWeek, GBHackers). Community discussion appeared on Reddit's r/Splunk and r/SecOpsDaily subreddits, reflecting practitioner interest in the patch urgency. The Hacker News included it in their weekly vulnerability recap, indicating broad industry awareness (The Hacker News). No significant researcher controversy or threat actor attribution has been publicly noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."