Description

A series of security patches have been issued by Splunk to address vulnerabilities found on Splunk Enterprise, Splunk Cloud Platform, and Splunk AI Toolkit. These vulnerabilities allow low-privilege users to gain access to data with limited access, expose sensitive information by logging, and create denial-of-service (DoS) scenarios where Splunk instances might be rendered unusable. The vulnerabilities include CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240. The first vulnerability (CVE-2026-20238) affects Splunk AI Toolkit releases prior to 5.7.3 owing to inadequate access control mechanisms which can permit access to AI-specific data. The second vulnerability (CVE-2026-20239) exposes sensitive data through logging operations for Splunk Enterprise and Splunk Cloud Platform. The third vulnerability (CVE-2026-20240) is related to insecure handling in coldToFrozen.sh scripts leading to the ability of attackers to induce DoS scenarios. Recommendations include updating affected releases to the latest available release, checking access control and role management, limiting access to the logs, being wary of any unusual queries, and validating backup and restore capabilities to mitigate DoS threats.