CVE Vulnerabilities

CVE-2026-20142

Insertion of Sensitive Information into Log File

Published: Feb 18, 2026 | Modified: Feb 23, 2026
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk _internal index could view the RSA accessKey value from the Authentication.conf file, in plain text.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
SplunkSplunk9.2.0 (including)9.2.11 (excluding)
SplunkSplunk9.3.0 (including)9.3.9 (excluding)
SplunkSplunk9.4.0 (including)9.4.7 (excluding)
SplunkSplunk10.0.0 (including)10.0.2 (excluding)

Potential Mitigations

References