Input validation error in Splunk Enterprise - CVE-2026-20240

 

Input validation error in Splunk Enterprise - CVE-2026-20240

Published: May 21, 2026


Vulnerability identifier: #VU132089
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20240
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper input validation in coldToFrozen.sh script in the splunk_archiver app when processing user-supplied file paths. A remote user can supply arbitrary file paths to rename critical Splunk directories to cause a denial of service.

Only users that do not hold the admin or power Splunk roles can exploit this issue, and instances that do not use the Splunk Archiver app are not impacted.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-20240

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.3.12, 9.4.11, 10.0.5, 10.2.2

External References

Related Security Bulletins