Junglewise Threat Intelligence

CVE-2026-20259: Splunk Enterprise improper access control in saved search ownership

CVE-2026-20259 · Severity: medium · CVSS 5.5 · Published 2026-06-10

Technologies: Splunk Cloud Platform, Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching machine-generated data. A security flaw in the web interface allows high-privileged users to reassign the ownership of saved searches to users outside of their authorized scope. This could lead to unauthorized access to sensitive search results or reports by users who should not have permission to view them.

Technical details

An improper access control vulnerability (CWE-284) exists in the Splunk Web component of Splunk Enterprise and Splunk Cloud Platform. The vulnerability resides in the ownership reassignment endpoint, which fails to properly validate the scope of the target user. An attacker with a role containing the 'edit_saved_search_owner' capability can exploit this to reassign saved searches to users outside their authorized administrative scope. This can lead to unauthorized data exposure if the new owner gains access to search results they were previously restricted from viewing. The issue is resolved in Splunk Enterprise versions 10.4.0, 10.2.4, 10.0.7, and various Splunk Cloud Platform maintenance releases.

Affected products

  • Splunk Splunk Enterprise 10.2.0 to 10.2.3, 10.0.0 to 10.0.6
  • Splunk Splunk Cloud Platform Below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, 9.3.2411.131

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: patched
  • 2026-06-10: advisory

References

Related threats