{"id":"CVE-2026-20239","title":"In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session coo…","summary":"In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session coo…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-532"],"vendor":"splunk","product":"splunk","affected":["splunk >= 10.0.0, < 10.0.5","splunk >= 10.2.0, < 10.2.2","splunk_cloud_platform >= 10.0.2503, < 10.0.2503.13","splunk_cloud_platform >= 10.1.2507, < 10.1.2507.21","splunk_cloud_platform >= 10.2.2510, < 10.2.2510.11","splunk_cloud_platform >= 10.3.2512, < 10.3.2512.8"],"patched":["splunk 10.2.2","splunk_cloud_platform 10.3.2512.8"],"published":"2026-05-20","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20239","references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-0503","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00485,"epssPercentile":0.40743,"ingestedAt":"2026-07-23T12:17:55.595Z","slug":"CVE-2026-20239","body":"## Overview\n\nIn Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.\n\n## Affected\n\n- `splunk >= 10.0.0, < 10.0.5`\n- `splunk >= 10.2.0, < 10.2.2`\n- `splunk_cloud_platform >= 10.0.2503, < 10.0.2503.13`\n- `splunk_cloud_platform >= 10.1.2507, < 10.1.2507.21`\n- `splunk_cloud_platform >= 10.2.2510, < 10.2.2510.11`\n- `splunk_cloud_platform >= 10.3.2512, < 10.3.2512.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `splunk 10.2.2`\n- `splunk_cloud_platform 10.3.2512.8`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}