Data Exposure in Splunk Enterprise Due to Misconfigured Search Head Cluster
CVE-2026-20138

6.8MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
18 February 2026

What is CVE-2026-20138?

In various versions of Splunk Enterprise, a security weakness has been identified that allows users with access to the Splunk _internal index within a Search Head Cluster setup to access sensitive secrets, including the integrationKey, secretKey, and appSecretKey. This exposure can lead to significant security risks, particularly in environments utilizing Duo Two-Factor Authentication. Proper configuration and access controls are essential to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Splunk Enterprise 10.0 < 10.0.2

Splunk Enterprise 9.4 < 9.4.7

Splunk Enterprise 9.3 < 9.3.9

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.