{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-12T20:23:09.832","vulnerabilities":[{"cve":{"id":"CVE-2026-20296","sourceIdentifier":"psirt@cisco.com","published":"2026-07-15T18:16:44.740","lastModified":"2026-07-24T18:18:34.027","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing Language (SPL) searches on their behalf as `splunk-system-user`, allowing for access to stored credentials and indexed data.<br><br>The vulnerability is possible because Deployment Server endpoints in Splunk Web do not validate Cross-Site Request Forgery (CSRF) tokens on GET requests, and caller-supplied input is not correctly neutralized before it is placed into an SPL search."}],"affected":[{"source":"psirt@cisco.com","affectedData":[{"vendor":"Splunk","product":"Splunk Enterprise","versions":[{"version":"10.4","lessThan":"10.4.1","versionType":"custom","status":"affected"},{"version":"10.2","lessThan":"10.2.5","versionType":"custom","status":"affected"},{"version":"10.0","lessThan":"10.0.8","versionType":"custom","status":"affected"},{"version":"9.4","lessThan":"9.4.13","versionType":"custom","status":"affected"}]},{"vendor":"Splunk","product":"Splunk Cloud Platform","versions":[{"version":"10.5.2605","lessThan":"10.5.2605.0","versionType":"custom","status":"affected"},{"version":"10.4.2604","lessThan":"10.4.2604.7","versionType":"custom","status":"affected"},{"version":"10.3.2512","lessThan":"10.3.2512.16","versionType":"custom","status":"affected"},{"version":"10.2.2510","lessThan":"10.2.2510.18","versionType":"custom","status":"affected"},{"version":"10.1.2507","lessThan":"10.1.2507.24","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-15T00:00:00+00:00","id":"CVE-2026-20296","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@cisco.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.4.0","versionEndExcluding":"9.4.13","matchCriteriaId":"8BEBD0A0-2CFD-4DDE-BF01-E64A9D7FD14C"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"10.0.8","matchCriteriaId":"BAF52B7B-401D-405E-B6A1-CA8C9AB33F85"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"10.2.5","matchCriteriaId":"58788CC8-B767-4050-A31A-47AC5DDF1EA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:10.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"C3506A1D-BEF7-4FAF-8B98-4977A35EEA59"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"10.1.2507","versionEndExcluding":"10.1.2507.24","matchCriteriaId":"FC8B8DC4-E9D1-4EF1-893F-62223F3FBB2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"10.2.2510","versionEndExcluding":"10.2.2510.18","matchCriteriaId":"24742A7B-F291-4FBD-91C1-45D7892507C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"10.3.2512","versionEndExcluding":"10.3.2512.16","matchCriteriaId":"0FA876EC-C7F6-4FAC-97B8-31B2608D0235"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"10.4.2604","versionEndExcluding":"10.4.2604.7","matchCriteriaId":"3B18F17C-6981-4262-8900-35FE6A9D33F2"}]}]}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-0702","source":"psirt@cisco.com","tags":["Vendor Advisory"]}]}}]}