#VU123985 Improper access control in Splunk Enterprise - CVE-2026-20164
Published: March 13, 2026
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper access restrictions. A remote user can access the "/splunkd/__raw/servicesNS/-/-/configs/conf-passwords" REST API endpoint, which exposes the hashed or plaintext password values that are stored in the passwords.conf configuration file