Junglewise Threat Intelligence

CVE-2026-20238: Splunk AI Toolkit incorrect authorization via srchFilter inheritance

CVE-2026-20238 · Severity: medium · CVSS 6.5 · Published 2026-05-20

Technologies: Splunk AI Toolkit. Vendors: Splunk.

Executive brief

A security flaw in the Splunk AI Toolkit allows low-privileged users to bypass data restrictions and view confidential information they should not be able to see. This occurs because a configuration error in the toolkit's security settings inadvertently overrides more restrictive data filters. Organizations using this toolkit may be at risk of unauthorized internal data exposure unless they update to the latest version.

Technical details

The Splunk AI Toolkit contains an 'authorize.conf' configuration file that incorrectly modifies the built-in 'user' role with a 'srchFilter' entry. Because the Splunk platform processes inherited search filters using the 'OR' SPL operator, this injected filter effectively overrides more restrictive filters defined on child or custom roles. An authenticated attacker with low privileges can exploit this logic to view data that should be restricted by their specific role's search filters. The vulnerability is resolved in version 5.7.3, and workarounds include manually removing the srchFilter line from the configuration file.

Affected products

  • Splunk AI Toolkit < 5.7.3

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory
  • 2026-05-20: patched: Fixed in version 5.7.3

References

Related threats