Cross-site request forgery in Splunk Enterprise - CVE-2026-20296
Published: July 21, 2026
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and execute arbitrary SPL searches on behalf of a victim user.
The vulnerability exists due to improper neutralization of special elements in Splunk Web Deployment Server endpoints when handling cross-site request forgery GET requests. A remote attacker can trick the victim into initiating a crafted browser request to disclose sensitive information and execute arbitrary SPL searches on behalf of a victim user.
User interaction is required, and the victim must hold a role with the list_deployment_server capability.