
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20298 is a sensitive information disclosure vulnerability in Splunk Enterprise and Splunk Cloud Platform that allows low-privileged users to view stored credential hashes via the |rest SPL command. Affected Splunk Enterprise versions include those below 10.4.1, 10.2.5, 10.0.8, and 9.4.13; affected Splunk Cloud Platform versions include those below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24. The vulnerability was published on July 15, 2026, and is currently undergoing NVD enrichment analysis. It carries a CVSS v3.1 base score of 5.3 (Medium), assigned by Cisco Systems (Splunk Advisory, GitHub Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability exists because the |rest SPL command, when used to query the /servicesNS/-/-/storage/passwords REST endpoint, returns the encr_password field in its results — a field that should be restricted to users holding the admin or power Splunk roles. An attacker with any valid low-privileged Splunk account can craft a simple SPL search using | rest /servicesNS/-/-/storage/passwords to retrieve stored credential hashes without requiring elevated permissions. The attack is network-based but rated High complexity, suggesting some preconditions (such as authenticated access) must be met (Splunk Advisory, GitHub Advisory).
Successful exploitation results in unauthorized disclosure of stored credential hashes (the encr_password field) from Splunk's password storage, which may include credentials for integrated third-party services, apps, and data inputs. While there is no integrity or availability impact, the confidentiality impact is rated High, as exposed hashes could be cracked offline or reused to access downstream systems, enabling lateral movement across an organization's infrastructure. The scope is limited to the Splunk instance itself, but given Splunk's role as a central logging and monitoring platform, credential exposure could have significant downstream consequences (Splunk Advisory, Feedly).
admin or power role — this could be a standard analyst or read-only account.| rest /servicesNS/-/-/storage/passwordsencr_password field, which contains stored credential hashes for configured apps and integrations.audit.log or _audit index) showing SPL searches containing | rest /servicesNS/-/-/storage/passwords executed by users without admin or power roles./servicesNS/-/-/storage/passwords REST endpoint./servicesNS/-/-/storage/passwords originating from non-administrative user sessions, particularly outside normal business hours.Splunk has released patched versions addressing this vulnerability. For Splunk Enterprise, upgrade to version 10.4.1, 10.2.5, 10.0.8, or 9.4.13 or later. For Splunk Cloud Platform, upgrade to version 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, or 10.1.2507.24 or later. As a workaround, restrict access to the /servicesNS/-/-/storage/passwords endpoint based on user roles and permissions, and review Splunk audit logs to identify any unauthorized credential disclosure prior to patching (Splunk Advisory, Feedly).
Security media outlets including SecurityWeek, GBHackers, CyberSecurityNews, and SecurityOnline covered this vulnerability as part of broader reporting on Splunk's July 2026 patch release, which addressed multiple Enterprise vulnerabilities including path traversal and information disclosure issues (SecurityWeek, GBHackers, SecurityOnline). Community coverage noted the risk of credential exposure in a platform commonly used as a central security monitoring hub, emphasizing the importance of prompt patching. No notable individual researcher commentary or threat actor attribution has been publicly reported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."