LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-20165

splunk · splunk

Published
CVSS6.3
Severitymedium
WeaknessCWE-532
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Description

In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, and 9.3.2411.124, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve sensitive information by inspecting the job's search log due to improper access control in the MongoClient logging channel.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-20165

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-20165.