Path Traversal: \'../filedir\' in Splunk Enterprise - CVE-2026-76353
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to delete arbitrary files.
The vulnerability exists due to path traversal in knowledge bundle delta processing when restricting removal paths to the staging directory. A remote user can submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager.