Improper Access Control in Splunk Enterprise
Advisory ID: SVD-2026-0609
CVE ID: CVE-2026-20259
Published: 2026-06-10
Last Update: 2026-06-10
CVSSv3.1 Score: 5.5, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
CWE: CWE-284
Bug ID: VULN-58322
Description
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability edit_saved_search_owner could reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks access control.
See Manage saved searches and reports and Define roles on the Splunk platform with capabilities in the Splunk documentation for more information.
Solution
Upgrade Splunk Enterprise to versions 10.4.0, 10.2.4 and 10.0.7, or higher.
Splunk is actively monitoring and patching Splunk Cloud Platform instances.
Product Status
| Product | Base Version | Component | Affected Version | Fix Version |
|---|---|---|---|---|
| Splunk Enterprise | 10.4 | Splunk Web | Not affected | 10.4.0 |
| Splunk Enterprise | 10.2 | Splunk Web | 10.2.0 to 10.2.3 | 10.2.4 |
| Splunk Enterprise | 10.0 | Splunk Web | 10.0.0 to 10.0.6 | 10.0.7 |
| Splunk Enterprise | 9.4 | Splunk Web | Not affected | N/A |
| Splunk Enterprise | 9.3 | Splunk Web | Not affected | N/A |
| Splunk Cloud Platform | 10.4.2604.0 | Splunk Web | Not affected | 10.4.2604.0 |
| Splunk Cloud Platform | 10.3.2512 | Splunk Web | Below 10.3.2512.12 | 10.3.2512.12 |
| Splunk Cloud Platform | 10.2.2510 | Splunk Web | Below 10.2.2510.15 | 10.2.2510.15 |
| Splunk Cloud Platform | 10.1.2507 | Splunk Web | Below 10.1.2507.23 | 10.1.2507.23 |
| Splunk Cloud Platform | 10.0.2503 | Splunk Web | Below 10.0.2503.14 | 10.0.2503.14 |
| Splunk Cloud Platform | 9.3.2411 | Splunk Web | Below 9.3.2411.131 | 9.3.2411.131 |
Mitigations and Workarounds
None
Detections
None
Severity
Splunk rates this vulnerability a 5.5, Medium, with a CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N.
Acknowledgments
Andres Perez, Splunk