Splunk released security updates for Splunk Enterprise that fix vulnerabilities attackers could use to access credentials and data, write files outside intended directories, or view stored credential hashes. The Splunk-specific issues are CVE-2026-20296, a high-severity command safeguards bypass; CVE-2026-20297, a high-severity path traversal flaw; and CVE-2026-20298, a medium-severity information disclosure bug. Fixes are in Splunk Enterprise 10.4.1, 10.2.5, 10.0.8, and 9.4.13.
Why it matters: Organizations running self-managed Splunk Enterprise should update promptly because these flaws could expose secrets and weaken controls on a central logging and security platform. Even without reported exploitation, affected servers often hold sensitive operational and credential data.
Ionut Arghire
2026.07.16
100% relevant
The existing tracked Splunk story is about a different flaw, CVE-2026-20253, in Splunk Enterprise; this article establishes a separate event covering new CVEs 2026-20296, 2026-20297, and 2026-20298.
← Back to all stories