CVE-2026-20144

MEDIUM

Splunk Enterprise <10.2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the the Splunk _internal index could view the Security Assertion Markup Language (SAML) configurations for Attribute query requests (AQRs) or Authentication extensions in plain text within the conf.log file, depending on which feature is configured.

Scores

CVSS v3 6.8
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-532
Status published
Products (2)
splunk/splunk 9.2.0 - 9.2.11
splunk/splunk_cloud_platform 9.3.2411 - 9.3.2411.120
Published Feb 18, 2026
Tracked Since Feb 18, 2026