CVE-2026-20204: Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise
In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform a Remote Code Execution (RCE) by uploading a malicious file to the `$SPLUNK_HOME/var/run/splunk/apptemp` directory due to improper handling and insufficient isolation of temporary files within the `apptemp` directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20204?
CVE-2026-20204 is classified as a low-severity vulnerability affecting specific versions of Splunk Enterprise and Splunk Cloud Platform.
How do I fix CVE-2026-20204?
To fix CVE-2026-20204, upgrade to Splunk Enterprise version 10.2.1 or later, or Splunk Cloud Platform version 10.4.2603.0 or later.
Which versions of Splunk are affected by CVE-2026-20204?
CVE-2026-20204 affects Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, as well as several versions of Splunk Cloud Platform.
What is the nature of the vulnerability in CVE-2026-20204?
CVE-2026-20204 involves improper handling and insufficient isolation of specific temporary files in the affected Splunk products.
Can exploit attempts for CVE-2026-20204 be detected?
While specific exploit attempts for CVE-2026-20204 may not be easily detectable, monitoring for unusual file access patterns could help identify potential vulnerabilities.