PT-2026-60234 · Splunk · Splunk Cloud Platform+1

CVE-2026-20297

·

Published

2026-07-15

·

Updated

2026-07-24

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.1 Splunk Enterprise versions prior to 10.2.5 Splunk Enterprise versions prior to 10.0.8 Splunk Enterprise versions prior to 9.4.13 Splunk Enterprise versions prior to 9.3.14 Splunk Cloud Platform versions prior to 10.5.2605.0 Splunk Cloud Platform versions prior to 10.4.2604.6 Splunk Cloud Platform versions prior to 10.2.2510.18 Splunk Cloud Platform versions prior to 10.1.2507.24
Description A path traversal issue exists in the app installation workflow. A user with a role containing the edit local apps and install apps capabilities can cause a legitimate app installation to write files outside the intended app directory, specifically into $SPLUNK HOME/etc/ and its subdirectories. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables such as file paths.
Recommendations Update Splunk Enterprise to version 10.4.1 or later. Update Splunk Enterprise to version 10.2.5 or later. Update Splunk Enterprise to version 10.0.8 or later. Update Splunk Enterprise to version 9.4.13 or later. Update Splunk Enterprise to version 9.3.14 or later. Update Splunk Cloud Platform to version 10.5.2605.0 or later. Update Splunk Cloud Platform to version 10.4.2604.6 or later. Update Splunk Cloud Platform to version 10.2.2510.18 or later. Update Splunk Cloud Platform to version 10.1.2507.24 or later.

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11316
CVE-2026-20297

Affected Products

Splunk Cloud Platform
Splunk Enterprise