CVE-2026-20240: Denial of Service through coldToFrozen.sh Script in Splunk Enterprise
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by exploiting the `coldToFrozen.sh` script in the `splunk_archiver` app to rename critical Splunk directories, making the instance non-functional.<br><br>The Denial of Service is possible because of missing input validation in the `coldToFrozen.sh` script, which accepts arbitrary file paths and renames them without restricting operations to safe directories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20240?
CVE-2026-20240 has been classified as a low-severity denial of service vulnerability.
How do I fix CVE-2026-20240?
To fix CVE-2026-20240, update Splunk Enterprise or Splunk Cloud Platform to the latest version beyond the specified vulnerable releases.
Which software versions are affected by CVE-2026-20240?
CVE-2026-20240 affects Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, as well as certain versions of Splunk Cloud Platform.
What exploits are associated with CVE-2026-20240?
CVE-2026-20240 could be exploited by a low-privileged user to execute denial of service attacks through the coldToFrozen.sh script.
Is CVE-2026-20240 present in Splunk Cloud Platform?
Yes, CVE-2026-20240 is present in multiple versions of Splunk Cloud Platform prior to 10.4.2603.1.