#VU123096 Unprotected storage of credentials in Splunk Enterprise - CVE-2026-20138
Published: February 19, 2026
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote user to gain access to other users' credentials.
The vulnerability exists due to application stored credentials in plain text. A remote user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk _internal index can view in plain text the integrationKey, secretKey, and appSecretKey secrets, generated by Duo Two-Factor Authentication for Splunk Enterprise.