CVE-2026-20238

Improper Access Control through Role Inheritance in Splunk AI Toolkit app

Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.4th percentile
Discovered by
Not disclosed
Published
May 20, 2026
Assigned by cisco

Description

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles.

Weakness: CWE-863

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • Splunk · Splunk AI Toolkit

Credit

Martin Muller, Splunk