CVE-2026-20144
Last modified
CVE-2026-20144 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the the Splunk _internal index could view the Security Assertion Markup Language (SAML) configurations for Attribute query requests (AQRs) or Authentication extensions in plain text within the conf.log file, depending on which feature is configured.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the the Splunk _internal index could view the Security Assertion Markup Language (SAML) configurations for Attribute query requests (AQRs) or Authentication extensions in plain text within the conf.log file, depending on which feature is configured.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | >= 9.2.0, < 9.2.11 |
| Splunk | Splunk | >= 9.3.0, < 9.3.8 |
| Splunk | Splunk | >= 9.4.0, < 9.4.7 |
| Splunk | Splunk | >= 10.0.0, < 10.0.2 |
| Splunk | Splunk Cloud Platform | >= 9.3.2411, < 9.3.2411.120 |
| Splunk | Splunk Cloud Platform | >= 10.0.2503, < 10.0.2503.9 |
| Splunk | Splunk Cloud Platform | >= 10.1.2507, < 10.1.2507.11 |
References
- https://advisory.splunk.com/advisories/SVD-2026-0209Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-20144?
How severe is CVE-2026-20144?
How do I fix CVE-2026-20144?
Are you affected by CVE-2026-20144?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
