CVE-2026-20297
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20297 is a path traversal vulnerability in the app installation workflow of Splunk Enterprise and Splunk Cloud Platform, titled "Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise." It affects Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24. The vulnerability was published on July 15, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Splunk Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). During the app installation workflow, the explicit_appname parameter in the App Install REST endpoint is not properly sanitized, allowing path traversal sequences to redirect file writes outside the intended app directory into $SPLUNK_HOME/etc/ and its subdirectories. Exploitation requires an authenticated user with both the edit_local_apps and install_apps capabilities, and is performed over the network without user interaction. The attack is not automatable per CISA's SSVC assessment (Splunk Advisory, GitHub Advisory).

Impact

A user with the required capabilities can write arbitrary files to $SPLUNK_HOME/etc/ and its subdirectories, potentially overwriting critical application configuration files, authentication settings, or other sensitive system files. This arbitrary file write primitive can be escalated to remote code execution by overwriting configuration files that influence Splunk's runtime behavior. The technical impact is rated as "total" by CISA, meaning confidentiality, integrity, and availability are all fully compromised upon successful exploitation (Splunk Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Splunk Enterprise or Splunk Cloud Platform instance running a vulnerable version (Enterprise < 10.4.1, 10.2.5, 10.0.8, 9.4.13, or 9.3.14; Cloud Platform < 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, or 10.1.2507.24).
  2. Obtain privileged credentials: Acquire credentials for a Splunk user account that holds both the edit_local_apps and install_apps capabilities — either through credential theft, insider access, or compromise of an admin account.
  3. Craft a malicious app package: Create a Splunk app archive (.tar.gz or .spl) that contains files with path traversal sequences (e.g., ../../) in their filenames or in the explicit_appname parameter, designed to write files to target locations within $SPLUNK_HOME/etc/.
  4. Install the malicious app: Submit the crafted app package via the App Install REST endpoint using the authenticated session, triggering the path traversal during the installation workflow.
  5. Achieve arbitrary file write: The installation process writes attacker-controlled files to $SPLUNK_HOME/etc/ or subdirectories, potentially overwriting configuration files (e.g., $SPLUNK_HOME/etc/system/local/authorize.conf or inputs.conf) to escalate privileges or achieve code execution (Splunk Advisory).

Indicators of compromise

  • Network: Authenticated HTTP POST requests to the Splunk App Install REST endpoint (/services/apps/local) from unexpected source IPs or at unusual times; large app package uploads from non-administrative workstations.
  • File System: Unexpected files appearing in $SPLUNK_HOME/etc/ or its subdirectories that do not correspond to a known installed app; modification timestamps on configuration files (e.g., authorize.conf, inputs.conf, outputs.conf) coinciding with app installation events.
  • Logs: Splunk splunkd.log entries showing app installation activity with unusual explicit_appname values containing path traversal sequences (e.g., ../, %2e%2e%2f); audit log entries (audit.log) recording app installs by accounts not typically performing administrative tasks.
  • Process: Unexpected processes spawned by the Splunk service account following an app installation event, which may indicate successful code execution via overwritten configuration.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability. For Splunk Enterprise, upgrade to version 10.4.1, 10.2.5, 10.0.8, 9.4.13, or 9.3.14 or later. For Splunk Cloud Platform, upgrade to version 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, or 10.1.2507.24 or later. As an interim workaround prior to patching, restrict the assignment of the edit_local_apps and install_apps capabilities to only trusted administrators, and audit existing role assignments to ensure no unauthorized users hold these capabilities (Splunk Advisory, GitHub Advisory).

Community reactions

The vulnerability received coverage from multiple security news outlets following its July 15, 2026 disclosure, including SecurityWeek, CyberSecurityNews, GBHackers, and SecurityOnline, which reported on it as part of a broader set of Splunk Enterprise vulnerabilities patched in the same release cycle (SecurityWeek, CyberSecurityNews, GBHackers). The Hacker News included it in their weekly vulnerability recap. Community discussion on Mastodon noted the path traversal and information disclosure issues together. No significant controversy or researcher dispute regarding the vulnerability's severity or scope has been observed.

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20296HIGH8.3
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20297HIGH7.2
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20298MEDIUM6.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20259MEDIUM5.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026
CVE-2026-20258MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management