Executive brief
Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching machine-generated data. A vulnerability in the archiving component allows a user with low-level access to rename critical system directories. This can lead to a complete service outage, making the Splunk instance non-functional and disrupting data operations.
Technical details
An improper input validation vulnerability (CWE-20) exists in the 'coldToFrozen.sh' script within the 'splunk_archiver' application. The script accepts arbitrary file paths and performs rename operations without restricting them to safe or intended directories. A remote attacker with low-privileged authenticated access (non-admin/non-power user) can provide malicious paths to rename critical Splunk system directories. This action results in a Denial of Service (DoS) by making the Splunk instance non-functional. The issue is resolved in Splunk Enterprise versions 10.2.2, 10.0.5, 9.4.11, 9.3.12, and various Splunk Cloud Platform maintenance releases.
Affected products
- Splunk Splunk Enterprise Below 10.2.2, 10.0.5, 9.4.11, 9.3.12
- Splunk Splunk Cloud Platform Below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, 9.3.2411.129
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory