CVE-2026-20166

EUVD-2026-11234
In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve the Observability Cloud API access token through the Discover Splunk Observability Cloud app due to improper access control. 

This vulnerability does not affect Splunk Enterprise versions below 9.4.9 and 9.3.10 because the Discover Splunk Observability Cloud app does not come with Splunk Enterprise.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
splunksplunk
10.0.0 ≤
𝑥
< 10.0.4
splunksplunk
10.2.0
splunksplunk_cloud_platform
10.0.2503 ≤
𝑥
< 10.0.2503.12
splunksplunk_cloud_platform
10.1.2507 ≤
𝑥
< 10.1.2507.16
splunksplunk_cloud_platform
10.2.2510 ≤
𝑥
< 10.2.2510.5
𝑥
= Vulnerable software versions