In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7...
Moderate severity
Unreviewed
Published
Feb 18, 2026
to the GitHub Advisory Database
•
Updated Feb 23, 2026
Description
Published by the National Vulnerability Database
Feb 18, 2026
Published to the GitHub Advisory Database
Feb 18, 2026
Last updated
Feb 23, 2026
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk
_internalindex could view the RSAaccessKeyvalue from the Authentication.conf file, in plain text.References