CVE-2026-20141

In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access the Splunk Monitoring Console App endpoints due to an improper access control. This could lead to a sensitive information disclosure.<br><br>The Monitoring Console app is a bundled app that comes with Splunk Enterprise. It is not available for download on SplunkBase, and is not installed on Splunk Cloud Platform instances. This vulnerability does not affect [Cloud Monitoring Console](https://help.splunk.com/en/splunk-cloud-platform/administer/admin-manual/10.2.2510/monitor-your-splunk-cloud-platform-deployment/introduction-to-the-cloud-monitoring-console).
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

History

23 Feb 2026, 14:46

Type Values Removed Values Added
CPE cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
First Time Splunk splunk
Splunk
Summary
  • (es) En las versiones de Splunk Enterprise anteriores a la 10.0.2, 10.0.3, 9.4.8 y 9.3.9, un usuario con pocos privilegios que no posea el rol de Splunk 'admin' podría acceder a los endpoints de la aplicación Splunk Monitoring Console debido a un control de acceso inadecuado. Esto podría llevar a una revelación de información sensible. La aplicación Monitoring Console es una aplicación incluida que viene con Splunk Enterprise. No está disponible para descargar en SplunkBase y no está instalada en instancias de Splunk Cloud Platform. Esta vulnerabilidad no afecta a [Cloud Monitoring Console](https://help.splunk.com/en/splunk-cloud-platform/administer/admin-manual/10.2.2510/monitor-your-splunk-cloud-platform-platform-deployment/introduction-to-the-cloud-monitoring-console).
References () https://advisory.splunk.com/advisories/SVD-2026-0206 - () https://advisory.splunk.com/advisories/SVD-2026-0206 - Vendor Advisory

18 Feb 2026, 18:24

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 18:24

Updated : 2026-02-23 14:46


NVD link : CVE-2026-20141

Mitre link : CVE-2026-20141

CVE.ORG link : CVE-2026-20141


JSON object : View

Products Affected

splunk

  • splunk
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor