Denial of Service through coldToFrozen.sh Script in Splunk Enterprise

Advisory ID: SVD-2026-0504

CVE ID: CVE-2026-20240

Published: 2026-05-20

Last Update: 2026-05-20

CVSSv3.1 Score: 7.1, High

CWE: CWE-20

Bug ID: VULN-60037

Description

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by exploiting the coldToFrozen.sh script in the splunk_archiver app to rename critical Splunk directories, making the instance non-functional.

The Denial of Service is possible because of missing input validation in the coldToFrozen.sh script, which accepts arbitrary file paths and renames them without restricting operations to safe directories.

See Set a retirement and archiving policy and About role-based user access in the Splunk documentation for more information.

Solution

Upgrade Splunk Enterprise to versions 10.2.2, 10.0.5, 9.4.11, 9.3.12, or higher.

Splunk is actively monitoring and patching Splunk Cloud Platform instances.

Product Status

ProductBase VersionComponentAffected VersionFix Version
Splunk Enterprise10.4Splunk ArchiverNot affectedN/A
Splunk Enterprise10.2Splunk Archiver10.2.0 to 10.2.110.2.2
Splunk Enterprise10.0Splunk Archiver10.0.0 to 10.0.410.0.5
Splunk Enterprise9.4Splunk Archiver9.4.0 to 9.4.109.4.11
Splunk Enterprise9.3Splunk Archiver9.3.0 to 9.3.119.3.12
Splunk Cloud Platform10.4.2603Splunk ArchiverBelow 10.4.2603.110.4.2603.1
Splunk Cloud Platform10.3.2512Splunk ArchiverBelow 10.3.2512.910.3.2512.9
Splunk Cloud Platform10.2.2510Splunk ArchiverBelow 10.2.2510.1110.2.2510.11
Splunk Cloud Platform10.1.2507Splunk ArchiverBelow 10.1.2507.2110.1.2507.21
Splunk Cloud Platform10.0.2503Splunk ArchiverBelow 10.0.2503.1310.0.2503.13
Splunk Cloud Platform9.3.2411Splunk ArchiverBelow 9.3.2411.1299.3.2411.129

Mitigations and Workarounds

Turn off the Splunk Archiver app. See Manage app and add-on objects in the Splunk documentation.

Note: If you use frozen bucket archiving with the splunk_archiver app, turning off the app will stop automated cold-to-frozen bucket transitions.

Detections

None

Severity

Splunk rates this vulnerability a 7.1, High, with a CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.

If you do not use the Splunk Archiver app, there should be no impact and the severity would be Informational.

Acknowledgments

Alex Hordijk (hordalex)