Splunk released security updates for multiple vulnerabilities in Splunk Enterprise and Splunk Cloud Platform, led by CVE-2026-20296, a high-severity flaw in the Deployment Server component of Splunk Web. The bug combines missing CSRF validation on GET requests with improper neutralization of user-controlled input, allowing an attacker to trick a user with the list_deployment_server capability into triggering arbitrary SPL searches as splunk-system-user. Successful exploitation could expose indexed data and stored credentials, with additional integrity and limited availability impact.
The update also addresses CVE-2026-20297 in the App Install REST endpoint and CVE-2026-20298 in the storage/passwords REST endpoint, which could enable path traversal and disclosure of stored credential hashes. Splunk published patched versions and mitigation guidance for customers, while Splunk Cloud Platform instances are being patched and monitored by Splunk. Splunk Enterprise administrators were advised to upgrade promptly and apply a configuration change to reduce exposure from the credential-hash disclosure issue.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk issued security updates for Splunk Enterprise and Splunk Cloud Platform to fix multiple flaws, including CVE-2026-20296, CVE-2026-20297, and CVE-2026-20298. The updates included fixed versions and mitigation guidance, with Splunk Cloud Platform customers being patched and monitored by Splunk.
CVE-2026-20296 was published as a high-severity Splunk vulnerability affecting Deployment Server functionality in Splunk Web. The flaw allows CSRF-triggered arbitrary SPL searches as splunk-system-user and can expose stored credentials and indexed data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.