CVE-2026-20238 Details
Description
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles.
A vulnerability exists in Splunk AI Toolkit versions prior to 5.7.3, allowing low-privileged users without 'admin' or 'power' roles to access confidential data restricted by 'srchFilter' configurations on custom roles. The issue arises because the app's 'authorize.conf' file modifies the default 'user' role, and Splunk's platform combines inherited search filters with the 'OR' operator. This combination allows the injected filter to override more restrictive filters on child roles, potentially exposing sensitive information.
Users are advised to upgrade Splunk AI Toolkit to version 5.7.3 or higher. If upgrading is not immediately possible, the app can be turned off until a patched version is available. Alternatively, the 'authorize.conf' file can be edited to remove the 'srchFilter' line or to add a 'srchFilter' line with an empty value, which will override the default 'srchFilter' entry. After making these changes, the Splunk platform instance should be restarted.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0502 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| splunk ai toolkit | >= 5.7.0, < 5.7.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | Initial Analysis | [email protected] |
| May 20, 2026 | New CVE Received | [email protected] |