#VU123091 Untrusted search path in Splunk Enterprise - CVE-2026-20143
Published: February 19, 2026
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path. A local user that can create a directory on the system drive where Splunk Enterprise is installed can write a malicious Python script into that directory and execute it with elevated privileges.
The vulnerability affects Windows installations only.