CVE-2026-20298: Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the /servicesNS/-/-/storage/passwords REST endpoint through the |rest Search Processing Language (SPL) command.<br><br>The exposure happens because the |rest SPL command returns the encrpassword field in the results of the /servicesNS/-/-/storage/passwords REST endpoint.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.1 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.5 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.8 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.5.2605.0 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.4.2604.6 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.3.2512.15 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.18 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.24 - Compensating control
Mitigate exposure by preventing low-privileged users (non-`admin`/non-`power` Splunk roles) from accessing the `/servicesNS/-/-/storage/passwords` REST endpoint via the `|rest` SPL command, since `|rest` exposes the `encr_password` field.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20298?
CVE-2026-20298 has a medium severity score of 5.3.
How do I fix CVE-2026-20298?
To fix CVE-2026-20298, upgrade to Splunk Enterprise version 10.4.1, 10.2.5, 10.0.8, 9.4.13 or later, and ensure your Splunk Cloud Platform version is 10.5.2605.0 or later.
Who is affected by CVE-2026-20298?
CVE-2026-20298 affects low-privileged users in Splunk who do not have 'admin' or 'power' roles.
What information is disclosed in CVE-2026-20298?
CVE-2026-20298 allows low-privileged users to view stored credential hashes through the storage/passwords REST endpoint.
What versions of Splunk are vulnerable to CVE-2026-20298?
Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, as well as certain versions of Splunk Cloud Platform are vulnerable to CVE-2026-20298.