CVE-2026-20137
Estado: AnalizadaMedia (5.7)—
In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the "admin" or "power" Splunk roles could bypass the SPL safeguards for risky commands when they create a Data Model that contains an injected SPL query within an object. They can bypass the safeguards by exploiting a path traversal vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 5.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-200
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-20137",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-20137",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-02-18T17:52:56.461958Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.5,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "Splunk",
"product": "Splunk Enterprise",
"versions": [
{
"status": "affected",
"version": "10.2",
"lessThan": "10.2.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "10.0",
"lessThan": "10.0.3",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.4",
"lessThan": "9.4.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.3",
"lessThan": "9.3.7",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.2",
"lessThan": "9.2.9",
"versionType": "custom"
}
]
},
{
"vendor": "Splunk",
"product": "Splunk Cloud Platform",
"versions": [
{
"status": "affected",
"version": "10.1.2507",
"lessThan": "10.1.2507.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "10.0",
"lessThan": "10.0.2503.9",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.3.2411",
"lessThan": "9.3.2411.112",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.3.2408",
"lessThan": "9.3.2408.122",
"versionType": "custom"
}
]
}
]
}
],
"published": "2026-02-18T18:24:22.637",
"references": [
{
"url": "https://advisory.splunk.com/advisories/SVD-2026-0202",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the \"admin\" or \"power\" Splunk roles could bypass the SPL safeguards for risky commands when they create a Data Model that contains an injected SPL query within an object. They can bypass the safeguards by exploiting a path traversal vulnerability."
},
{
"lang": "es",
"value": "En las versiones de Splunk Enterprise anteriores a 10.2.0, 10.0.3, 9.4.5, 9.3.7 y 9.2.9, y en las versiones de Splunk Cloud Platform anteriores a 10.1.2507.0, 10.0.2503.9, 9.3.2411.112 y 9.3.2408.122, un usuario con pocos privilegios que no posea los roles de Splunk 'admin' o 'power' podría eludir las salvaguardas de SPL para comandos arriesgados cuando crea un Modelo de Datos que contiene una consulta SPL inyectada dentro de un objeto. Puede eludir las salvaguardas explotando una vulnerabilidad de salto de ruta."
}
],
"lastModified": "2026-06-17T10:17:11.473",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE00218E-F8B2-42DA-9E4E-D7A00B657B93",
"versionEndExcluding": "9.2.9",
"versionStartIncluding": "9.2.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6257ADA-AB6E-4679-A41B-BCE79CE8D573",
"versionEndExcluding": "9.3.7",
"versionStartIncluding": "9.3.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30970DF3-6DA7-4FAB-B234-3226F47F9C87",
"versionEndExcluding": "9.4.5",
"versionStartIncluding": "9.4.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB313879-7BD8-411A-B503-01689F0B326E",
"versionEndExcluding": "10.0.3",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2EEE3994-A508-46E7-81D6-C038C68235E7",
"versionEndExcluding": "9.3.2408.122",
"versionStartIncluding": "9.3.2408"
},
{
"criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C929336-F50D-4AFC-BCF9-CCA5BF89E599",
"versionEndExcluding": "9.3.2411.112",
"versionStartIncluding": "9.3.2411"
},
{
"criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62714243-8A5F-4908-BD39-7B1026B8E7D7",
"versionEndExcluding": "10.0.2503.9",
"versionStartIncluding": "10.0.2503"
},
{
"criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56CBDDE1-EBD2-4E82-A7B7-CE4F0F27BF21"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@cisco.com"
}