---
id: CVE-2026-20239
title: >-
  In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud
  Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and
  10.0.2503.13, a user with a role that has access to the `_internal` index
  could view session coo…
summary: >-
  In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud
  Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and
  10.0.2503.13, a user with a role that has access to the `_internal` index
  could view session coo…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-532
vendor: splunk
product: splunk
affected:
  - 'splunk >= 10.0.0, < 10.0.5'
  - 'splunk >= 10.2.0, < 10.2.2'
  - 'splunk_cloud_platform >= 10.0.2503, < 10.0.2503.13'
  - 'splunk_cloud_platform >= 10.1.2507, < 10.1.2507.21'
  - 'splunk_cloud_platform >= 10.2.2510, < 10.2.2510.11'
  - 'splunk_cloud_platform >= 10.3.2512, < 10.3.2512.8'
patched:
  - splunk 10.2.2
  - splunk_cloud_platform 10.3.2512.8
published: '2026-05-20'
updated: '2026-07-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20239'
references:
  - url: 'https://advisory.splunk.com/advisories/SVD-2026-0503'
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00485
epssPercentile: 0.40888
ingestedAt: '2026-07-23T12:17:55.595Z'
---

## Overview

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.

## Affected

- `splunk >= 10.0.0, < 10.0.5`
- `splunk >= 10.2.0, < 10.2.2`
- `splunk_cloud_platform >= 10.0.2503, < 10.0.2503.13`
- `splunk_cloud_platform >= 10.1.2507, < 10.1.2507.21`
- `splunk_cloud_platform >= 10.2.2510, < 10.2.2510.11`
- `splunk_cloud_platform >= 10.3.2512, < 10.3.2512.8`

## Remediation

Upgrade past the affected range:

- `splunk 10.2.2`
- `splunk_cloud_platform 10.3.2512.8`
