CVE-2026-20298
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20298 is a sensitive information disclosure vulnerability in Splunk Enterprise and Splunk Cloud Platform that allows low-privileged users to view stored credential hashes via the |rest SPL command. Affected Splunk Enterprise versions include those below 10.4.1, 10.2.5, 10.0.8, and 9.4.13; affected Splunk Cloud Platform versions include those below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24. The vulnerability was published on July 15, 2026, and is currently undergoing NVD enrichment analysis. It carries a CVSS v3.1 base score of 5.3 (Medium), assigned by Cisco Systems (Splunk Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability exists because the |rest SPL command, when used to query the /servicesNS/-/-/storage/passwords REST endpoint, returns the encr_password field in its results — a field that should be restricted to users holding the admin or power Splunk roles. An attacker with any valid low-privileged Splunk account can craft a simple SPL search using | rest /servicesNS/-/-/storage/passwords to retrieve stored credential hashes without requiring elevated permissions. The attack is network-based but rated High complexity, suggesting some preconditions (such as authenticated access) must be met (Splunk Advisory, GitHub Advisory).

Impact

Successful exploitation results in unauthorized disclosure of stored credential hashes (the encr_password field) from Splunk's password storage, which may include credentials for integrated third-party services, apps, and data inputs. While there is no integrity or availability impact, the confidentiality impact is rated High, as exposed hashes could be cracked offline or reused to access downstream systems, enabling lateral movement across an organization's infrastructure. The scope is limited to the Splunk instance itself, but given Splunk's role as a central logging and monitoring platform, credential exposure could have significant downstream consequences (Splunk Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target Splunk Enterprise or Splunk Cloud Platform instance running an affected version (Enterprise < 10.4.1, 10.2.5, 10.0.8, or 9.4.13; Cloud Platform < 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, or 10.1.2507.24).
  2. Obtain low-privileged credentials: Acquire any valid Splunk user account that does not hold the admin or power role — this could be a standard analyst or read-only account.
  3. Log in to Splunk: Authenticate to the Splunk web interface or use the Splunk REST API with the low-privileged credentials.
  4. Execute malicious SPL search: In the Splunk search bar, run the following SPL command: | rest /servicesNS/-/-/storage/passwords
  5. Extract credential hashes: Review the returned results for the encr_password field, which contains stored credential hashes for configured apps and integrations.
  6. Offline cracking or reuse: Attempt to crack the retrieved hashes offline using tools such as Hashcat or John the Ripper, or attempt to reuse them against integrated third-party systems (Splunk Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Splunk audit logs (audit.log or _audit index) showing SPL searches containing | rest /servicesNS/-/-/storage/passwords executed by users without admin or power roles.
  • Logs: Splunk search history entries from low-privileged accounts querying the /servicesNS/-/-/storage/passwords REST endpoint.
  • Network: Unusual REST API calls to /servicesNS/-/-/storage/passwords originating from non-administrative user sessions, particularly outside normal business hours.
  • Behavioral: Low-privileged user accounts running REST-based SPL commands that are atypical for their role or search history pattern.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability. For Splunk Enterprise, upgrade to version 10.4.1, 10.2.5, 10.0.8, or 9.4.13 or later. For Splunk Cloud Platform, upgrade to version 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, or 10.1.2507.24 or later. As a workaround, restrict access to the /servicesNS/-/-/storage/passwords endpoint based on user roles and permissions, and review Splunk audit logs to identify any unauthorized credential disclosure prior to patching (Splunk Advisory, Feedly).

Community reactions

Security media outlets including SecurityWeek, GBHackers, CyberSecurityNews, and SecurityOnline covered this vulnerability as part of broader reporting on Splunk's July 2026 patch release, which addressed multiple Enterprise vulnerabilities including path traversal and information disclosure issues (SecurityWeek, GBHackers, SecurityOnline). Community coverage noted the risk of credential exposure in a platform commonly used as a central security monitoring hub, emphasizing the importance of prompt patching. No notable individual researcher commentary or threat actor attribution has been publicly reported.

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20296HIGH8.3
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20297HIGH7.2
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20298MEDIUM6.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20259MEDIUM5.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026
CVE-2026-20258MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management