« Volver al listado

CVE-2026-20296

Estado: AnalizadaAlta (8.3)—

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing Language (SPL) searches on their behalf as `splunk-system-user`, allowing for access to stored credentials and indexed data.<br><br>The vulnerability is possible because Deployment Server endpoints in Splunk Web do not validate Cross-Site Request Forgery (CSRF) tokens on GET requests, and caller-supplied input is not correctly neutralized before it is placed into an SPL search.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVSS requiere interacción del usuario (UI:R) → T1203. Impactos: acceso a credenciales almacenadas (CWE-352 CSRF + SPL injection) → T1552.007 (credenciales en archivos); lectura de datos indexados → T1005; búsquedas SPL en contexto del sistema → T1185.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-20296",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-20296",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-15T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@cisco.com",
      "affectedData": [
        {
          "vendor": "Splunk",
          "product": "Splunk Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "10.4",
              "lessThan": "10.4.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.2",
              "lessThan": "10.2.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.0",
              "lessThan": "10.0.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.4",
              "lessThan": "9.4.13",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Splunk",
          "product": "Splunk Cloud Platform",
          "versions": [
            {
              "status": "affected",
              "version": "10.5.2605",
              "lessThan": "10.5.2605.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.4.2604",
              "lessThan": "10.4.2604.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.3.2512",
              "lessThan": "10.3.2512.16",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.2.2510",
              "lessThan": "10.2.2510.18",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.1.2507",
              "lessThan": "10.1.2507.24",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-15T18:16:44.740",
  "references": [
    {
      "url": "https://advisory.splunk.com/advisories/SVD-2026-0702",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@cisco.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing Language (SPL) searches on their behalf as `splunk-system-user`, allowing for access to stored credentials and indexed data.<br><br>The vulnerability is possible because Deployment Server endpoints in Splunk Web do not validate Cross-Site Request Forgery (CSRF) tokens on GET requests, and caller-supplied input is not correctly neutralized before it is placed into an SPL search."
    }
  ],
  "lastModified": "2026-07-24T18:18:34.027",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BEBD0A0-2CFD-4DDE-BF01-E64A9D7FD14C",
              "versionEndExcluding": "9.4.13",
              "versionStartIncluding": "9.4.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAF52B7B-401D-405E-B6A1-CA8C9AB33F85",
              "versionEndExcluding": "10.0.8",
              "versionStartIncluding": "10.0.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58788CC8-B767-4050-A31A-47AC5DDF1EA3",
              "versionEndExcluding": "10.2.5",
              "versionStartIncluding": "10.2.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:10.4.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3506A1D-BEF7-4FAF-8B98-4977A35EEA59"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC8B8DC4-E9D1-4EF1-893F-62223F3FBB2C",
              "versionEndExcluding": "10.1.2507.24",
              "versionStartIncluding": "10.1.2507"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24742A7B-F291-4FBD-91C1-45D7892507C5",
              "versionEndExcluding": "10.2.2510.18",
              "versionStartIncluding": "10.2.2510"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FA876EC-C7F6-4FAC-97B8-31B2608D0235",
              "versionEndExcluding": "10.3.2512.16",
              "versionStartIncluding": "10.3.2512"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B18F17C-6981-4262-8900-35FE6A9D33F2",
              "versionEndExcluding": "10.4.2604.7",
              "versionStartIncluding": "10.4.2604"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@cisco.com"
}