Splunk Security Updates – 3 May 2026

Splunk has released security updates to fix several vulnerabilities in Splunk MCP Server, Splunk Enterprise, and Splunk Cloud Platform.

The addressed vulnerabilities could allow the attacker to obtain sensitive information, manipulate data, execute arbitrary code, and gain access to the affected systems.

Sample of the addressed vulnerabilities:

1. Splunk MCP Server Sensitive Information Disclosure Vulnerability (CVE-2026- 20205):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Obtain Information

2. Splunk Enterprise Improper Handling and Insufficient Isolation of Specific Temporary Files (CVE-2026-20204):

  • CVSS: 7.1
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Splunk Security Updates

References