4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Description
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload into the `realname`, `tz`, or `email` parameters of the `/splunkd/__raw/services/authentication/users/username` REST API endpoint when they change a password. This could potentially lead to a client‑side denial‑of‑service (DoS). The malicious payload might significantly slow page load times or render Splunk Web temporarily unresponsive.
Basic Information
ID
CVE-2026-20139
Source
cisco
Published
Feb 18, 2026 at 16:45
Affected Product
Vendor
Splunk
Product
Splunk Enterprise
Version
10.0
Affected Versions
Splunk Splunk Enterprise 10.0
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Cloud Platform 10.2.2510
Splunk Splunk Cloud Platform 10.1.2507
Splunk Splunk Cloud Platform 10.0.2503
Splunk Splunk Cloud Platform 9.3.2411
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Cloud Platform 10.2.2510
Splunk Splunk Cloud Platform 10.1.2507
Splunk Splunk Cloud Platform 10.0.2503
Splunk Splunk Cloud Platform 9.3.2411