{"id":"CVE-2026-20240","title":"In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not ho…","summary":"In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not ho…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"splunk","product":"splunk","affected":["splunk >= 9.3.0, < 9.3.12","splunk >= 9.4.0, < 9.4.11","splunk >= 10.0.0, < 10.0.5","splunk >= 10.2.0, < 10.2.2","splunk_cloud_platform >= 9.3.2411, < 9.3.2411.129","splunk_cloud_platform >= 10.0.2503, < 10.0.2503.13","splunk_cloud_platform >= 10.1.2507, < 10.1.2507.21","splunk_cloud_platform >= 10.2.2510, < 10.2.2510.11","splunk_cloud_platform >= 10.3.2512, < 10.3.2512.9","splunk_cloud_platform = 10.4.2603"],"patched":["splunk 10.2.2","splunk_cloud_platform 10.3.2512.9"],"published":"2026-05-20","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20240","references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-0504","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00396,"epssPercentile":0.33676,"ingestedAt":"2026-07-23T12:17:55.618Z","slug":"CVE-2026-20240","body":"## Overview\n\nIn Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by exploiting the `coldToFrozen.sh` script in the `splunk_archiver` app to rename critical Splunk directories, making the instance non-functional.<br><br>The Denial of Service is possible because of missing input validation in the `coldToFrozen.sh` script, which accepts arbitrary file paths and renames them without restricting operations to safe directories.\n\n## Affected\n\n- `splunk >= 9.3.0, < 9.3.12`\n- `splunk >= 9.4.0, < 9.4.11`\n- `splunk >= 10.0.0, < 10.0.5`\n- `splunk >= 10.2.0, < 10.2.2`\n- `splunk_cloud_platform >= 9.3.2411, < 9.3.2411.129`\n- `splunk_cloud_platform >= 10.0.2503, < 10.0.2503.13`\n- `splunk_cloud_platform >= 10.1.2507, < 10.1.2507.21`\n- `splunk_cloud_platform >= 10.2.2510, < 10.2.2510.11`\n- `splunk_cloud_platform >= 10.3.2512, < 10.3.2512.9`\n- `splunk_cloud_platform = 10.4.2603`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `splunk 10.2.2`\n- `splunk_cloud_platform 10.3.2512.9`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}