CVE-2026-20298
Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise
Severity
Medium 5.3
CVSS 3.1
Exploited
Not listed
EPSS
0.002
14.2th percentile
Discovered by
Not disclosed
Published
Jul 15, 2026
Assigned by cisco
Description
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the `/servicesNS/-/-/storage/passwords` REST endpoint through the `|rest` Search Processing Language (SPL) command.<br><br>The exposure happens because the `|rest` SPL command returns the `encr_password` field in the results of the `/servicesNS/-/-/storage/passwords` REST endpoint.
Weakness: CWE-200
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Cloud Platform | SIEM & Log Management | cna-assigner |
| Cisco | Splunk Enterprise | SIEM & Log Management | cna-assigner |
Vendor-reported products (2)
- Splunk · Splunk Enterprise
- Splunk · Splunk Cloud Platform