Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityai-platform-security

Splunk fixes flaws exposing internal data and enabling denial of service

Updated 1d agoFirst seen May 22, 20268 sources

Splunk released patches for three vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit, including a high-severity denial-of-service bug and two issues that can expose sensitive data. CVE-2026-20240 affects the splunk_archiver app, where a low-privileged user can abuse the coldToFrozen.sh script to rename critical directories and render an instance inoperable. CVE-2026-20239 stems from improper output sanitization in the TcpChannel component and can leak session cookies and cleartext HTTP response bodies into the _internal log index, while CVE-2026-20238 is an access-control weakness in the Splunk AI Toolkit that can bypass intended search restrictions and expose restricted data.

Splunk said the issues were fixed in updated releases, including AI Toolkit 5.7.3 for CVE-2026-20238, and urged customers to upgrade affected deployments. The company also published interim mitigations for organizations that cannot patch immediately, including restricting access to the _internal index to administrators, disabling the Splunk Archiver application, reviewing inherited roles and permissions, and removing the problematic srchFilter entry from local configuration where applicable. The advisories highlight risks to both platform availability and the confidentiality of operational data stored in Splunk environments.

Share:
Splunk fixes flaws exposing internal data and enabling denial of service
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 22, 20261mo ago

CVE-2026-25606 is recorded in vulnerability databases

CVE-2026-25606, a SQL injection flaw in STER, was recorded as a newly received vulnerability by cvd@cert.pl. The entry noted that the issue allows authenticated attackers to access sensitive data and that the vendor fixed it in STER version 9.5.

May 20, 20261mo ago

Splunk discloses and patches three vulnerabilities across its products

Splunk disclosed and patched CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240 affecting Splunk AI Toolkit, Splunk Enterprise, and Splunk Cloud Platform. The flaws could expose restricted data, leak sensitive information into internal logs, or allow a low-privileged user to trigger denial-of-service conditions, and Splunk issued upgrade and mitigation guidance.

May 1, 20262mo ago

CERT Polska discloses three STER vulnerabilities fixed in version 9.5

CERT Polska published details of three vulnerabilities affecting STER versions before 9.5: SQL injection (CVE-2026-25606), weak password encoding (CVE-2026-25607), and cleartext transmission over unencrypted TCP (CVE-2026-25608). The disclosure credited Michelin CERT for the report and stated the issues were fixed in STER version 9.5.

Mar 11, 20264mo ago

Splunk publishes advisory SVD-2026-0302

Splunk published vulnerability advisory SVD-2026-0302. Based on the available metadata, this represents a separate Splunk disclosure event distinct from the earlier SVD-2026-0201 advisory and the later May 2026 multi-CVE disclosure.

SVD-2026-0302 | Splunk Vulnerability Disclosure
Feb 4, 20265mo ago

Splunk publishes advisory SVD-2026-0201

Splunk published vulnerability advisory SVD-2026-0201. Based on the reference metadata, this advisory represents an earlier Splunk disclosure event preceding the later May 2026 vulnerability reporting already in the timeline.

SVD-2026-0201 | Splunk Vulnerability Disclosure
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.