Description
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the `/servicesNS/-/-/storage/passwords` REST endpoint through the `|rest` Search Processing Language (SPL) command.<br><br>The exposure happens because the `|rest` SPL command returns the `encr_password` field in the results of the `/servicesNS/-/-/storage/passwords` REST endpoint.
Published: 2026-07-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged user lacking admin or power roles can retrieve encrypted credential hashes stored by Splunk via the /servicesNS/-/-/storage/passwords REST endpoint, because the |rest SPL command includes the encr_password field in its output. This results in the accidental disclosure of sensitive credential information (CWE‑200).

Affected Systems

The issue affects Splunk Enterprise releases below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform releases below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24.

Risk and Exploitability

With a CVSS score of 5.3 the vulnerability is considered moderate. The EPSS score is below 1 %, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit it by running a |rest command in the Splunk query DSL when logged into the platform, which is possible for any user without admin or power privileges, making the attack path local to the Splunk environment and dependent on legitimate user access. No privileged escalation is required, but the exposed credential hashes could be leveraged in further attacks if harvested.

Generated by OpenCVE AI on July 31, 2026 at 03:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Splunk Enterprise 10.4.1 or later or Splunk Cloud Platform 10.5.2605.0 or later, which contain the fix for the improper exposure of the encr_password field.
  • Restrict or remove the use of the |rest SPL command for users that do not have admin or power roles, or configure role‑based permissions so that only privileged users can query the /servicesNS/-/-/storage/passwords endpoint.
  • Monitor Splunk logs for unexpected access to the /servicesNS/-/-/storage/passwords REST endpoint and investigate any unauthorized attempts to retrieve credential hashes.

Generated by OpenCVE AI on July 31, 2026 at 03:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Cloud Platform
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Cloud Platform
Splunk splunk Enterprise

Wed, 15 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the `/servicesNS/-/-/storage/passwords` REST endpoint through the `|rest` Search Processing Language (SPL) command.<br><br>The exposure happens because the `|rest` SPL command returns the `encr_password` field in the results of the `/servicesNS/-/-/storage/passwords` REST endpoint.
Title Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Cloud Platform Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-07-16T03:55:51.583Z

Reserved: 2025-10-08T11:59:15.407Z

Link: CVE-2026-20298

cve-icon Vulnrichment

Updated: 2026-07-15T17:52:10.359Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor