Executive brief
Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching machine-generated data. A security flaw allows users with low-level access to view sensitive information, such as session cookies and private response data, that should be restricted. This could allow an internal user to gain unauthorized access to other user sessions or sensitive corporate data.
Technical details
A sensitive information disclosure vulnerability (CWE-532) exists in the TcpChannel component of Splunk Enterprise and Splunk Cloud Platform. The issue is caused by missing output buffer sanitization, which leads the system to log full I/O buffer contents at the WARN level when discarding data during socket errors. An attacker with a role granted access to the `_internal` index can search these logs to retrieve session cookies and sensitive response bodies. Exploitation requires the attacker to have an authenticated account with specific log access permissions and depends on the occurrence of socket errors to trigger the logging of unsanitized data. Splunk has released patches for Enterprise versions and is updating Cloud Platform instances.
Affected products
- Splunk Splunk Enterprise 10.2.0 to 10.2.1, 10.0.0 to 10.0.4
- Splunk Splunk Cloud Platform Below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory
- 2026-05-20: patched