
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20297 is a path traversal vulnerability in the app installation workflow of Splunk Enterprise and Splunk Cloud Platform, titled "Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise." It affects Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24. The vulnerability was published on July 15, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Splunk Advisory, GitHub Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). During the app installation workflow, the explicit_appname parameter in the App Install REST endpoint is not properly sanitized, allowing path traversal sequences to redirect file writes outside the intended app directory into $SPLUNK_HOME/etc/ and its subdirectories. Exploitation requires an authenticated user with both the edit_local_apps and install_apps capabilities, and is performed over the network without user interaction. The attack is not automatable per CISA's SSVC assessment (Splunk Advisory, GitHub Advisory).
A user with the required capabilities can write arbitrary files to $SPLUNK_HOME/etc/ and its subdirectories, potentially overwriting critical application configuration files, authentication settings, or other sensitive system files. This arbitrary file write primitive can be escalated to remote code execution by overwriting configuration files that influence Splunk's runtime behavior. The technical impact is rated as "total" by CISA, meaning confidentiality, integrity, and availability are all fully compromised upon successful exploitation (Splunk Advisory, GitHub Advisory).
edit_local_apps and install_apps capabilities — either through credential theft, insider access, or compromise of an admin account.../../) in their filenames or in the explicit_appname parameter, designed to write files to target locations within $SPLUNK_HOME/etc/.$SPLUNK_HOME/etc/ or subdirectories, potentially overwriting configuration files (e.g., $SPLUNK_HOME/etc/system/local/authorize.conf or inputs.conf) to escalate privileges or achieve code execution (Splunk Advisory)./services/apps/local) from unexpected source IPs or at unusual times; large app package uploads from non-administrative workstations.$SPLUNK_HOME/etc/ or its subdirectories that do not correspond to a known installed app; modification timestamps on configuration files (e.g., authorize.conf, inputs.conf, outputs.conf) coinciding with app installation events.splunkd.log entries showing app installation activity with unusual explicit_appname values containing path traversal sequences (e.g., ../, %2e%2e%2f); audit log entries (audit.log) recording app installs by accounts not typically performing administrative tasks.Splunk has released patched versions addressing this vulnerability. For Splunk Enterprise, upgrade to version 10.4.1, 10.2.5, 10.0.8, 9.4.13, or 9.3.14 or later. For Splunk Cloud Platform, upgrade to version 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, or 10.1.2507.24 or later. As an interim workaround prior to patching, restrict the assignment of the edit_local_apps and install_apps capabilities to only trusted administrators, and audit existing role assignments to ensure no unauthorized users hold these capabilities (Splunk Advisory, GitHub Advisory).
The vulnerability received coverage from multiple security news outlets following its July 15, 2026 disclosure, including SecurityWeek, CyberSecurityNews, GBHackers, and SecurityOnline, which reported on it as part of a broader set of Splunk Enterprise vulnerabilities patched in the same release cycle (SecurityWeek, CyberSecurityNews, GBHackers). The Hacker News included it in their weekly vulnerability recap. Community discussion on Mastodon noted the path traversal and information disclosure issues together. No significant controversy or researcher dispute regarding the vulnerability's severity or scope has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."