Path Traversal: \'dir/../../filename\' in Splunk Enterprise - CVE-2026-76344
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to write files to arbitrary locations.
The vulnerability exists due to path traversal in the Search Dispatch REST API when using a search identifier to create a dispatch directory. A remote user can supply a crafted search identifier to write dispatch metadata to an arbitrary location on the host.