CVE-2026-20238
MEDIUMDescription
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2026-20238? +
How severe is CVE-2026-20238? +
How do I check if I'm vulnerable to CVE-2026-20238? +
Related Vulnerabilities
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 …
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently …
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default …
The vulnerability allows an unauthenticated attacker to access information in PAM database.
An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 …
This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated …