Splunk Enterprise for Windows Flaw Enables DLL Hijacking, SYSTEM Access
A vulnerability in Splunk Enterprise for Windows, identified as CVE-2026-20140, has been disclosed. It is a local privilege escalation (LPE) vulnerability caused by DLL search-order hijacking and has been assigned a CVSSv3.1 score of 7.7, classified as…
A vulnerability in Splunk Enterprise for Windows, identified as CVE-2026-20140, has been disclosed. It is a local privilege escalation (LPE) vulnerability caused by DLL search-order hijacking and has been assigned a CVSSv3.1 score of 7.7, classified as high severity. Splunk issued an advisory (SVD-2026-0205) on February 18, 2026, to address this issue.
The vulnerability affects Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.8, 9.3.9, and 9.2.12. A low-privileged Windows user can exploit this flaw by creating a directory on the system drive where Splunk is installed and introducing a malicious DLL. Upon restarting the Splunk service, it inadvertently loads the malicious DLL, granting SYSTEM-level privileges to the injected code.
This exploitation technique leverages Windows' predictable DLL search paths and corresponds to the CWE-427 (Untrusted Search Path) weakness. Although the attack requires local access and user interaction, it does not necessitate initial privileges. The CVSS vector CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H indicates a low attack vector but significant impact on confidentiality, integrity, and availability.
Product Base Version Affected Versions Fix Version
Splunk Enterprise 10.2 Not affected 10.2.0
A vulnerability in Splunk Enterprise for Windows, identified as CVE-2026-20140, has been disclosed.
Splunk Enterprise 10.0 10.0.0 to 10.0.2 10.0.3
Splunk Enterprise 9.4 9.4.0 to 9.4.7 9.4.8
Splunk Enterprise 9.3 9.3.0 to 9.3.8 9.3.9
Splunk Enterprise 9.2 9.2.0 to 9.2.11 9.2.12
Administrators are strongly advised to upgrade to the patched versions: 10.2.0, 10.0.3, 9.4.8, 9.3.9, or 9.2.12. Non-Windows deployments are not affected by this vulnerability, thus classifying the severity as informational for those cases.
There are no workarounds other than restricting directory creation on the system drive or monitoring for unusual behavior during Splunk service startups. Administrators should also review logs for unexpected DLL loads using available tools.
Prompt patching is essential to mitigate potential exploitation by threat actors, even though no active exploits have been reported yet. The high severity score underscores the urgency of addressing this vulnerability.
Based on reporting by GBHackers.
