cbcvebase.
CVE-2026-20259
published 2026-06-10

CVE-2026-20259: In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23…

PriorityP433medium5.5CVSS 3.1
AVNACLPRHUINSUCHILAN
EPSS
0.19%
8.7th percentile
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability `edit_saved_search_owner` could reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks access control.

Affected

9 ranges
VendorProductVersion rangeFixed in
splunksplunk>= 10.0.0 < 10.0.710.0.7
splunksplunk>= 10.2.0 < 10.2.410.2.4
splunksplunk_cloud_platform>= 10.0.2503 < 10.0.2503.1410.0.2503.14
splunksplunk_cloud_platform>= 10.1.2507 < 10.1.2507.2310.1.2507.23
splunksplunk_cloud_platform>= 10.2.2510 < 10.2.2510.1510.2.2510.15
splunksplunk_cloud_platform>= 10.3.2512 < 10.3.2512.1210.3.2512.12
splunksplunk_cloud_platform>= 9.3.2411 < 9.3.2411.1319.3.2411.131
splunksplunk_enterprise>= 10.0 < 10.0.710.0.7
splunksplunk_enterprise>= 10.2 < 10.2.410.2.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.