Executive brief
Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching large datasets. A security flaw in the application installation process allows high-privileged users to write files to unauthorized locations on the server. This could lead to a full system compromise, data loss, or service disruption by overwriting critical configuration files.
Technical details
A path traversal vulnerability (CWE-22) exists in the App Install REST endpoint of Splunk Enterprise and Splunk Cloud Platform. The flaw is located in the 'explicit_appname' parameter within the app installation workflow, which fails to properly restrict the installation path. An attacker with a role containing 'edit_local_apps' and 'install_apps' capabilities can exploit this to write files into the '$SPLUNK_HOME/etc/' directory and its subdirectories. This could allow for the overwriting of sensitive configuration files or the introduction of malicious scripts. The issue is resolved in Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, 9.4.13, 9.3.14, and corresponding Splunk Cloud Platform updates.
Affected products
- Splunk Splunk Enterprise < 10.4.1, < 10.2.5, < 10.0.8, < 9.4.13, < 9.3.14
- Splunk Splunk Cloud Platform < 10.5.2605.0, < 10.4.2604.6, < 10.2.2510.18, < 10.1.2507.24
Timeline
- 2026-07-15: advisory: Initial disclosure by Splunk and NVD publication.
- 2026-07-15: patched: Fixes released in multiple Splunk Enterprise and Cloud versions.