CVE-2024-36991
Splunk Enterprise vulnerability analysis and mitigation

Overview

A high-severity path traversal vulnerability (CVE-2024-36991) was discovered in Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10. The vulnerability affects the /modules/messaging/ endpoint in Splunk Web, the platform's user interface, and was discovered by Danylo Dmytriiev. The vulnerability received a CVSS v3.1 score of 7.5 (High) and was disclosed on July 1, 2024 (Splunk Advisory).

Technical details

The vulnerability exists due to a flaw in the Python os.path.join function, which removes the drive letter from path tokens if the drive in the token matches the drive in the built path. This behavior can be exploited through specially crafted GET requests to perform directory traversal, allowing access to files or directories outside the restricted directory. The vulnerability only affects instances where Splunk Web is enabled and does not require authentication for exploitation (HelpNet Security, SonicWall Blog).

Impact

Successful exploitation of this vulnerability allows attackers to perform directory listings on the Splunk endpoint and gain unauthorized access to sensitive files in the system. With over 230,000 internet-exposed servers running Splunk, the potential impact is significant. The vulnerability enables attackers to read arbitrary files on the operating system, potentially exposing sensitive information (Cyber Security News).

Exploitability

The vulnerability can be exploited remotely by sending crafted GET requests to vulnerable instances. Multiple proof-of-concept exploits have been published, including one that performs bulk scanning for vulnerable internet-facing endpoints. An attacker only needs remote access to the instance, either over the Internet or a local network, to exploit this vulnerability (HelpNet Security).

Mitigation and workarounds

Organizations are advised to upgrade to the fixed versions: Splunk Enterprise 9.2.2, 9.1.5, or 9.0.10 or higher. As a temporary workaround, administrators can disable Splunk Web, though upgrading to a patched version is the recommended solution. Splunk's Threat Research team has provided a search query to detect exploitation attempts against the /modules/messaging endpoint (Splunk Advisory).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20296HIGH8.3
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20297HIGH7.2
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20298MEDIUM6.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20259MEDIUM5.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026
CVE-2026-20258MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesJun 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management