CVE-2026-20163: Remote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk Enterprise
In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that contains the high-privilege capability `edit_cmd` could execute arbitrary shell commands using the `unarchive_cmd` parameter for the `/splunkd/__upload/indexing/preview` REST endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20163?
CVE-2026-20163 is classified as a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2026-20163?
To mitigate CVE-2026-20163, upgrade to Splunk Enterprise versions 10.2.0 or above, 10.0.4 or above, 9.4.9 or above, or 9.3.10 or above.
What software is affected by CVE-2026-20163?
CVE-2026-20163 affects Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, 9.3.10 and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124.
What is the impact of CVE-2026-20163?
The impact of CVE-2026-20163 allows unauthorized users to execute arbitrary commands on the server, which can lead to data breaches.
How can I determine if I am vulnerable to CVE-2026-20163?
To determine vulnerability to CVE-2026-20163, compare your Splunk Enterprise or Splunk Cloud Platform version against the specified vulnerable versions.