Home

Description

In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access the Splunk Monitoring Console App endpoints due to an improper access control. This could lead to a sensitive information disclosure.<br><br>The Monitoring Console app is a bundled app that comes with Splunk Enterprise. It is not available for download on SplunkBase, and is not installed on Splunk Cloud Platform instances. This vulnerability does not affect [Cloud Monitoring Console](https://help.splunk.com/en/splunk-cloud-platform/administer/admin-manual/10.2.2510/monitor-your-splunk-cloud-platform-deployment/introduction-to-the-cloud-monitoring-console).

PUBLISHED Reserved 2025-10-08 | Published 2026-02-18 | Updated 2026-02-18 | Assigner cisco




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Product status

10.0 (custom) before 10.0.3
affected

9.4 (custom) before 9.4.8
affected

9.3 (custom) before 9.3.9
affected

Credits

Mohammad Fahad Khan (fahadkhan01)

References

advisory.splunk.com/advisories/SVD-2026-0206

cve.org (CVE-2026-20141)

nvd.nist.gov (CVE-2026-20141)

Download JSON