CVE-2026-20238
Improper Access Control through Role Inheritance in Splunk AI Toolkit app
Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.003
25.3th percentile
Discovered by
Not disclosed
Published
May 20, 2026
Assigned by cisco
Description
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles.
Weakness: CWE-863
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Apps & Add-ons | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Splunk · Splunk AI Toolkit
Credit
Martin Muller, Splunk