Information disclosure in Splunk Enterprise - CVE-2026-20298
Published: July 21, 2026
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the /servicesNS/-/-/storage/passwords REST endpoint when accessing the endpoint through the |rest Search Processing Language command. A remote user can access the endpoint to disclose sensitive information.
The exposed data includes stored credential hashes in the encr_password field, and the issue affects users that do not hold the admin or power Splunk roles.