Junglewise Threat Intelligence

CVE-2026-20240: Splunk Enterprise Denial of Service in coldToFrozen script

CVE-2026-20240 · Severity: medium · CVSS 6.5 · Published 2026-05-20

Technologies: Splunk Cloud Platform, Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching machine-generated data. A vulnerability in the archiving component allows a user with low-level access to rename critical system directories. This can lead to a complete service outage, making the Splunk instance non-functional and disrupting data operations.

Technical details

An improper input validation vulnerability (CWE-20) exists in the 'coldToFrozen.sh' script within the 'splunk_archiver' application. The script accepts arbitrary file paths and performs rename operations without restricting them to safe or intended directories. A remote attacker with low-privileged authenticated access (non-admin/non-power user) can provide malicious paths to rename critical Splunk system directories. This action results in a Denial of Service (DoS) by making the Splunk instance non-functional. The issue is resolved in Splunk Enterprise versions 10.2.2, 10.0.5, 9.4.11, 9.3.12, and various Splunk Cloud Platform maintenance releases.

Affected products

  • Splunk Splunk Enterprise Below 10.2.2, 10.0.5, 9.4.11, 9.3.12
  • Splunk Splunk Cloud Platform Below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, 9.3.2411.129

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory

References

Related threats