CVE-2026-20259
Analyzed Analyzed - Analysis Complete
Privilege Escalation in Splunk Enterprise via Saved Search Ownership

Publication date: 2026-06-10

Last updated on: 2026-06-12

Assigner: Cisco Systems, Inc.

Description
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability `edit_saved_search_owner` could reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks access control.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-10
Last Modified
2026-06-12
Generated
2026-06-17
AI Q&A
2026-06-10
EPSS Evaluated
2026-06-16
NVD
EUVD
Affected Vendors & Products
Showing 7 associated CPEs
Vendor Product Version / Range
splunk splunk From 10.0.0 (inc) to 10.0.7 (exc)
splunk splunk From 10.2.0 (inc) to 10.2.4 (exc)
splunk splunk_cloud_platform From 10.3.2512 (inc) to 10.3.2512.12 (exc)
splunk splunk_cloud_platform From 10.1.2507 (inc) to 10.1.2507.23 (exc)
splunk splunk_cloud_platform From 10.2.2510 (inc) to 10.2.2510.15 (exc)
splunk splunk_cloud_platform From 10.0.2503 (inc) to 10.0.2503.14 (exc)
splunk splunk_cloud_platform From 9.3.2411 (inc) to 9.3.2411.131 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-20259 is an improper access control vulnerability found in certain versions of Splunk Enterprise and Splunk Cloud Platform. Specifically, users who have a high-privilege capability called edit_saved_search_owner can reassign the ownership of saved searches to users outside their authorized scope. This happens because the endpoint responsible for ownership reassignment lacks proper access control.

Impact Analysis

This vulnerability can lead to unauthorized access or privilege escalation within the affected Splunk environments. By reassigning saved search ownership to unauthorized users, an attacker could potentially manipulate or access saved searches they should not have permission to, which could compromise data integrity or confidentiality.

Detection Guidance

Splunk has not identified any detections for this issue, and no specific detection commands or methods are provided.

Mitigation Strategies

The recommended solution is to upgrade Splunk Enterprise to versions 10.4.0, 10.2.4, or 10.0.7, or higher.

For Splunk Cloud Platform, upgrade to the specified patched versions: 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, or 9.3.2411.131.

No mitigations or workarounds are provided.

Compliance Impact

This vulnerability allows a user with a high-privilege capability to reassign saved search ownership to unauthorized users due to improper access control. Such unauthorized access or privilege escalation could potentially lead to exposure or misuse of sensitive data.

While the provided information does not explicitly mention specific impacts on compliance with standards like GDPR or HIPAA, unauthorized access to data or administrative functions can generally increase the risk of non-compliance with data protection regulations that require strict access controls and accountability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20259. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart