CVE-2026-20296: SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the listdeploymentserver capability into running arbitrary Search Processing Language (SPL) searches on their behalf as splunk-system-user, allowing for access to stored credentials and indexed data.<br><br>The vulnerability is possible because Deployment Server endpoints in Splunk Web do not validate Cross-Site Request Forgery (CSRF) tokens on GET requests, and caller-supplied input is not correctly neutralized before it is placed into an SPL search.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.1 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.5 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.8 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.5.2605.0 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.4.2604.7 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.3.2512.16 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.18 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20296?
CVE-2026-20296 has a severity rating of 8.3, classified as high.
How do I fix CVE-2026-20296?
To fix CVE-2026-20296, upgrade to Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, 9.4.13 or Splunk Cloud Platform versions 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, 10.1.2507.24.
What type of vulnerability is CVE-2026-20296?
CVE-2026-20296 is a Cross-Site Request Forgery (CSRF) vulnerability.
What impact does CVE-2026-20296 have?
The impact of CVE-2026-20296 allows an attacker to trick a user into executing arbitrary commands.
Which versions of Splunk are affected by CVE-2026-20296?
Versions of Splunk Enterprise below 10.4.1, 10.2.5, 10.0.8, 9.4.13 and certain versions of Splunk Cloud Platform are affected by CVE-2026-20296.