Splunk patches high-severity RCE in enterprise and cloud

Splunk has patched a high-severity remote code execution (RCE) vulnerability that should sit near the top of every security team’s maintenance queue. Tracked as CVE-2026-20204, the flaw was disclosed on 15 April 2026 and carries a CVSS 3.1 score of 7.1. Splunk says it stems from improper handling and insufficient isolation of temporary files in Splunk Web’s apptemp directory.

The risk is serious because a low-privileged user, one without the admin or power roles, could upload a malicious file to $SPLUNK_HOME/var/run/splunk/apptemp and achieve remote code execution. In other words, this is not a theoretical weakness in a minor component. It affects a platform many organisations use to collect, investigate and operationalise security telemetry.

Affected Splunk Enterprise versions are 10.2.0, 10.0.0 to 10.0.4, 9.4.0 to 9.4.9 and 9.3.0 to 9.3.10. Splunk’s fix versions are 10.2.1, 10.0.5, 9.4.10 and 9.3.11 or later. Splunk Cloud Platform customers are being patched by Splunk, with affected Cloud versions listed in the advisory.

Some wider April patch coverage recommends 10.2.2 for Enterprise 10.2 users because it captures additional fixes beyond this specific CVE.

Treat Splunk like Tier-0 infrastructure

The immediate recommendation is simple: upgrade. 

Where that cannot happen quickly, Splunk says disabling Splunk Web is a possible workaround for affected instances. Its documentation shows admins can set startwebserver = 0 in web.conf, then restart the instance.

But the broader lesson is architectural. 

SIEMs, observability platforms and telemetry systems often hold privileged data, credentials, internal network knowledge and incident response workflows. If compromised, they can become both a target and a launchpad.

Admins should review exposed Splunk Web interfaces, restrict access to management networks, audit low-privileged accounts, monitor unusual uploads and validate that temporary directories are not being abused.

Security platforms should not be treated as ordinary business applications. In practice, they are Tier-0 assets and patch windows should reflect that.

You might also be interested

About The Author

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.