CVE-2026-20297

Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise

Severity
High 7.2
CVSS 3.1
Exploited
Not listed
EPSS
0.005
38.9th percentile
Discovered by
Not disclosed
Published
Jul 15, 2026
Assigned by cisco

Description

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the `edit_local_apps` and `install_apps` capabilities could cause a legitimate app installation to write files outside the intended app directory, into `$SPLUNK_HOME/etc/` and its subdirectories.<br><br>The vulnerability is caused by a path traversal in the app installation workflow, which does not restrict the installation path to the intended app directory.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (2)
  • Splunk · Splunk Enterprise
  • Splunk · Splunk Cloud Platform

Credit

Vinay Manivel, Splunk