Vulnerability Details CVE-2026-20239
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.6%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-20239
-
cpe:2.3:a:splunk:splunk:*
-
cpe:2.3:a:splunk:splunk:10.0.0
-
cpe:2.3:a:splunk:splunk:10.0.1
-
cpe:2.3:a:splunk:splunk:10.0.2
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503.10
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503.11
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503.12
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503.5
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503.6
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503.7
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503.8
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.0.2503.9
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.1
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.10
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.11
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.12
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.15
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.16
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.17
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.19
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.20
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.4
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.6
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.8
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.10
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.3
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.4
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.5
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.7
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.9
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.3.2512
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.3.2512.5
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.3.2512.6