Path traversal in Splunk Enterprise - CVE-2026-20297
Published: July 21, 2026
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote user to write files outside the intended app directory.
The vulnerability exists due to path traversal in the App Install REST endpoint when processing a legitimate app installation through the explicit_appname parameter. A remote privileged user can supply a crafted app installation path to write files outside the intended app directory.
Exploitation requires a role that includes the edit_local_apps and install_apps capabilities, and file writes are limited to $SPLUNK_HOME/etc/ and its subdirectories.