Splunk released patches for three vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit, including a high-severity denial-of-service bug and two issues that can expose sensitive data. CVE-2026-20240 affects the splunk_archiver app, where a low-privileged user can abuse the coldToFrozen.sh script to rename critical directories and render an instance inoperable. CVE-2026-20239 stems from improper output sanitization in the TcpChannel component and can leak session cookies and cleartext HTTP response bodies into the _internal log index, while CVE-2026-20238 is an access-control weakness in the Splunk AI Toolkit that can bypass intended search restrictions and expose restricted data.
Splunk said the issues were fixed in updated releases, including AI Toolkit 5.7.3 for CVE-2026-20238, and urged customers to upgrade affected deployments. The company also published interim mitigations for organizations that cannot patch immediately, including restricting access to the _internal index to administrators, disabling the Splunk Archiver application, reviewing inherited roles and permissions, and removing the problematic srchFilter entry from local configuration where applicable. The advisories highlight risks to both platform availability and the confidentiality of operational data stored in Splunk environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-25606, a SQL injection flaw in STER, was recorded as a newly received vulnerability by cvd@cert.pl. The entry noted that the issue allows authenticated attackers to access sensitive data and that the vendor fixed it in STER version 9.5.
Splunk disclosed and patched CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240 affecting Splunk AI Toolkit, Splunk Enterprise, and Splunk Cloud Platform. The flaws could expose restricted data, leak sensitive information into internal logs, or allow a low-privileged user to trigger denial-of-service conditions, and Splunk issued upgrade and mitigation guidance.
CERT Polska published details of three vulnerabilities affecting STER versions before 9.5: SQL injection (CVE-2026-25606), weak password encoding (CVE-2026-25607), and cleartext transmission over unencrypted TCP (CVE-2026-25608). The disclosure credited Michelin CERT for the report and stated the issues were fixed in STER version 9.5.
Splunk published vulnerability advisory SVD-2026-0302. Based on the available metadata, this represents a separate Splunk disclosure event distinct from the earlier SVD-2026-0201 advisory and the later May 2026 multi-CVE disclosure.
Splunk published vulnerability advisory SVD-2026-0201. Based on the reference metadata, this advisory represents an earlier Splunk disclosure event preceding the later May 2026 vulnerability reporting already in the timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceadvisory.splunk.com
Open sourceadvisory.splunk.com
Open sourcecert.pl
Open sourceadvisory.splunk.com
Open sourceadvisory.splunk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.