Data Core Systems, Romania’s Post

🔴 Splunk Patches Three Vulnerabilities. One Could Expose Stored Credentials to a Hijacked Session. Fixes Available. A set of three Splunk Enterprise vulnerabilities worth flagging for anyone running the platform. None are confirmed as exploited in the wild, and there's no public proof-of-concept for any of them at this stage, but given where Splunk sits in most security operations, they're worth folding into your review promptly. Why it's on the radar: Splunk is the beating heart of a lot of SOC environments. It holds credentials and indexed log data, which is precisely the kind of material an attacker wants to reach. Vulnerabilities that touch stored secrets, even ones that need specific conditions to trigger, deserve attention rather than a wait-and-see approach. The three findings: 💡 CVE-2026-20296 (High, 8.3): The most significant of the batch. Deployment Server endpoints skip CSRF validation on GET requests, and caller input flows into SPL searches without proper neutralization. An attacker who tricks a user holding the list_deployment_server capability into interacting with a crafted request can run arbitrary SPL as the system user, opening access to stored credentials and indexed data. 💡 CVE-2026-20297 (High, 7.2): A path traversal issue during app installation. A user with the right app-installation capabilities can cause a legitimate install to write files outside the intended directory, into the Splunk home configuration path. 💡 CVE-2026-20298 (Medium, 5.3): A credential hash exposure. A low-privileged user without admin or power roles can retrieve stored credential hashes via a specific REST-based SPL command. Who is affected: Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, with one of the flaws also reaching 9.3 versions below 9.3.14. Several Splunk Cloud Platform releases are affected as well. Fixed builds are available across all lines. Recommended actions: 💡 Upgrade Splunk Enterprise to 10.4.1, 10.2.5, 10.0.8, 9.4.13, or 9.3.14 and above. 💡 Splunk Cloud Platform instances are being updated on Splunk's side, so no manual action needed there. 💡 Review who holds the deployment and app-installation capabilities referenced above, and tighten assignments where possible. 💡 Keep an eye on Deployment Server endpoints for unusual search or access activity as general hygiene. All three fixes are available and no active exploitation has been reported. The most serious of the batch needs a social engineering step to work, which raises the bar somewhat, but the sensitivity of what Splunk holds makes applying these updates the sensible move rather than deferring them. A quick version check and upgrade closes the door on all three. #SplunkSecurity #CVE202620296 #Splunk #PatchManagement #ThreatIntelligence #InfoSec #EnterpriseIT #SYSADMIN #VulnerabilityManagement #SOC #SIEMSecurity #CyberResilience #ITSecurity #SecurityAdvisory #CSRF #PrivilegeEscalation #DataProtection #CredentialSecurity

  • No alternative text description for this image

To view or add a comment, sign in

Explore content categories