5.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Description
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds a Splunk role that contains the high-privilege capability `edit_saved_search_owner` could reassign saved search ownership to users outside their authorized scope. The ownership reassignment endpoint lacks access control.
Basic Information
ID
CVE-2026-20259
Source
cisco
Published
Jun 10, 2026 at 17:16
Modified
Jun 10, 2026 at 18:24
Affected Product
Vendor
Splunk
Product
Splunk Enterprise
Version
10.2
Affected Versions
Splunk Splunk Enterprise 10.2
Splunk Splunk Enterprise 10.0
Splunk Splunk Cloud Platform 10.3.2512
Splunk Splunk Cloud Platform 10.2.2510
Splunk Splunk Cloud Platform 10.1.2507
Splunk Splunk Cloud Platform 10.0.2503
Splunk Splunk Cloud Platform 9.3.2411
Splunk Splunk Enterprise 10.0
Splunk Splunk Cloud Platform 10.3.2512
Splunk Splunk Cloud Platform 10.2.2510
Splunk Splunk Cloud Platform 10.1.2507
Splunk Splunk Cloud Platform 10.0.2503
Splunk Splunk Cloud Platform 9.3.2411