CVE-2026-20202: Improper Input Validation during User Account Creation in Splunk Enterprise
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a specially crafted username that includes a null byte or a non-UTF-8 percent-encoded byte due to improper input validation.<br><br>This could lead to inconsistent conversion of usernames into a proper format for storage and account management inconsistencies, such as being unable to edit or delete affected users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20202?
CVE-2026-20202 has a high severity due to the improper input validation that could lead to unauthorized access during user account creation.
How do I fix CVE-2026-20202?
To address CVE-2026-20202, upgrade to Splunk Enterprise version 10.2.2 or higher, or the respective updated versions of Splunk Cloud Platform.
What versions are affected by CVE-2026-20202?
CVE-2026-20202 affects Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, 9.3.11, and various versions of Splunk Cloud Platform below 10.4.2603.0.
What type of vulnerability is CVE-2026-20202?
CVE-2026-20202 is an improper input validation vulnerability affecting user account creation processes.
Can CVE-2026-20202 allow attackers to gain unauthorized access?
Yes, CVE-2026-20202 can potentially allow attackers to gain unauthorized access due to improper input validation.