#VU123093 Cleartext storage of sensitive information in Splunk Enterprise - CVE-2026-20142
Published: February 19, 2026
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to application stores sensitive information in configuration files. A remote user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk _internal index can view in plain text the RSA accessKey value from the Authentication.conf file.