Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H 10.2 (custom) before 10.2.2
affected
10.0 (custom) before 10.0.5
affected
10.3.2512 (custom) before 10.3.2512.8
affected
10.2.2510 (custom) before 10.2.2510.11
affected
10.1.2507 (custom) before 10.1.2507.21
affected
10.0.2503 (custom) before 10.0.2503.13
affected
Description
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.
Problem types
Product status
10.0 (custom) before 10.0.5
10.2.2510 (custom) before 10.2.2510.11
10.1.2507 (custom) before 10.1.2507.21
10.0.2503 (custom) before 10.0.2503.13
Credits
Charlie Huggard, Splunk
References
advisory.splunk.com/advisories/SVD-2026-0503