CVE-2026-20238
Improper Access Control through Role Inheritance in Splunk AI Toolkit app
Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.4th percentile
Discovered by
Not disclosed
Published
May 20, 2026
Assigned by cisco
Description
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles.
Weakness: CWE-863
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- Splunk · Splunk AI Toolkit
Credit
Martin Muller, Splunk