Executive brief
Splunk Enterprise, a widely-used data analytics and monitoring platform, contains a flaw in how it processes knowledge bundle deltas on cluster managers. A user with limited privileges (no admin or power role) can craft a specially designed bundle to delete arbitrary files that the Splunk process can access, potentially compromising system integrity and causing service disruptions.
Technical details
The vulnerability is an authorization bypass combined with improper path validation in the knowledge bundle delta processing logic. A user without admin or power roles can submit a crafted knowledge bundle delta to a cluster manager's REST API endpoint. The vulnerable code fails to restrict deletion paths to the staging directory and does not properly enforce authorization boundaries, allowing an attacker to delete arbitrary files accessible to the Splunk Enterprise process. This affects system integrity and may disrupt service availability. Splunk has issued patches in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
Affected products
- Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, and 9.4.14
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Patches released in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14