CVE-2026-20297

Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise

Severity
High 7.2
CVSS 3.1
Exploited
Not listed
EPSS
0.006
46.0th percentile
Discovered by
Not disclosed
Published
Jul 15, 2026
Assigned by cisco

Description

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the `edit_local_apps` and `install_apps` capabilities could cause a legitimate app installation to write files outside the intended app directory, into `$SPLUNK_HOME/etc/` and its subdirectories.<br><br>The vulnerability is caused by a path traversal in the app installation workflow, which does not restrict the installation path to the intended app directory.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Cisco Splunk Cloud Platform SIEM & Log Management cna-assigner
Cisco Splunk Enterprise SIEM & Log Management cna-assigner
Vendor-reported products (2)
  • Splunk · Splunk Enterprise
  • Splunk · Splunk Cloud Platform

Credit

Vinay Manivel, Splunk

Something wrong here?