Data Exposure in Splunk Enterprise Due to Misconfigured Search Head Cluster
CVE-2026-20138
What is CVE-2026-20138?
In various versions of Splunk Enterprise, a security weakness has been identified that allows users with access to the Splunk _internal index within a Search Head Cluster setup to access sensitive secrets, including the integrationKey, secretKey, and appSecretKey. This exposure can lead to significant security risks, particularly in environments utilizing Duo Two-Factor Authentication. Proper configuration and access controls are essential to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Splunk Enterprise 10.0 < 10.0.2
Splunk Enterprise 9.4 < 9.4.7
Splunk Enterprise 9.3 < 9.3.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved