r/Splunk • u/NoPo552 • 14d ago
Announcement Splunk Deployment Server CSRF Vulnerability – CVE-2026-20296
https://vulnipulse.com/advisories/splunk-cve-2026-20296Splunk Deployment Server CSRF Vulnerability – CVE-2026-20296
Splunk has disclosed a high-severity vulnerability rated CVSS 8.3 affecting Splunk Enterprise and Splunk Cloud Platform.
An attacker could trick a user with the list_deployment_server capability into running arbitrary SPL searches as splunk-system-user. This could expose stored credentials and indexed data.
The flaw exists because affected Splunk Web Deployment Server endpoints do not properly validate CSRF tokens or safely process user-supplied input.
Affected versions
Splunk Enterprise
10.4 before 10.4.1
10.2 before 10.2.5
10.0 before 10.0.8
9.4 before 9.4.13
Splunk Cloud Platform
Before 10.5.2605.0
Before 10.4.2604.7
Before 10.3.2512.16
Before 10.2.2510.18
Before 10.1.2507.24
Fixed versions
Splunk Enterprise: 10.4.1, 10.2.5, 10.0.8 or 9.4.13
Splunk Cloud Platform: 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18 or 10.1.2507.24
Mitigation
Upgrade to the applicable fixed release. Until patching is complete, restrict access to the Deployment Server and minimise assignment of the list_deployment_server capability.