{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T08:09:11.710","vulnerabilities":[{"cve":{"id":"CVE-2026-20163","sourceIdentifier":"psirt@cisco.com","published":"2026-03-11T17:16:56.607","lastModified":"2026-06-17T10:17:14.720","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that contains the high-privilege capability `edit_cmd` could execute arbitrary shell commands using the `unarchive_cmd` parameter for the `/splunkd/__upload/indexing/preview` REST endpoint."},{"lang":"es","value":"En las versiones de Splunk Enterprise anteriores a 10.2.0, 10.0.4, 9.4.9 y 9.3.10, y las versiones de Splunk Cloud Platform anteriores a 10.2.2510.5, 10.0.2503.12, 10.1.2507.16 y 9.3.2411.124, un usuario que posee un rol que contiene la capacidad de alto privilegio 'edit_cmd' podría ejecutar comandos de shell arbitrarios utilizando el parámetro 'unarchive_cmd' para el endpoint REST /splunkd/__upload/indexing/preview."}],"affected":[{"source":"psirt@cisco.com","affectedData":[{"vendor":"Splunk","product":"Splunk Enterprise","versions":[{"version":"10.0","lessThan":"10.0.4","versionType":"custom","status":"affected"},{"version":"9.4","lessThan":"9.4.9","versionType":"custom","status":"affected"},{"version":"9.3","lessThan":"9.3.10","versionType":"custom","status":"affected"}]},{"vendor":"Splunk","product":"Splunk Cloud Platform","versions":[{"version":"10.2.2510","lessThan":"10.2.2510.5","versionType":"custom","status":"affected"},{"version":"10.0.2503","lessThan":"10.0.2503.12","versionType":"custom","status":"affected"},{"version":"10.1.2507","lessThan":"10.1.2507.16","versionType":"custom","status":"affected"},{"version":"9.3.2411","lessThan":"9.3.2411.124","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-12T03:55:43.201014Z","id":"CVE-2026-20163","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@cisco.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"9.3.10","matchCriteriaId":"BFBDF80A-51CC-470E-977C-96ABBF89162D"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"9.4.9","matchCriteriaId":"ACAC2D08-9ED6-4E58-A999-0EE2025C69FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"10.0.4","matchCriteriaId":"1E7483F3-FE84-42B9-A2E7-6E89B110BA31"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"9.3.2411","versionEndExcluding":"9.3.2411.124","matchCriteriaId":"5198A912-AABA-40D1-8DE1-958E6584501B"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.2503","versionEndExcluding":"10.0.2503.12","matchCriteriaId":"FA248FBD-6AFF-492C-93A8-17EAA7C07FC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"10.1.2507","versionEndExcluding":"10.1.2507.16","matchCriteriaId":"17E11C59-CC22-48AA-A969-717D4D527019"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"10.2.2510","versionEndExcluding":"10.2.2510.5","matchCriteriaId":"6609708F-A13F-4E4E-9883-C11659BD6C3C"}]}]}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-0302","source":"psirt@cisco.com","tags":["Vendor Advisory"]}]}}]}