CVE-2026-20139 | Splunk Enterprise/Cloud Platform REST API Endpoint username realname/tz/email resource consumption (SVD-2026-0204 / Nessus ID 299411)
A vulnerability classified as problematic has been found in Splunk Enterprise and Cloud Platform. The affected element is an unknown function of the file /splunkd/__raw/services/authentication/users/username of the component REST API Endpoint. The manipulation of the argument realname/tz/email leads to resource consumption.
This vulnerability is listed as CVE-2026-20139. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.