Splunk Enterprise/Cloud <10.4.1 Path Traversal: App installs write outside app dir
CVE-2026-20297 Published on July 15, 2026
Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the `edit_local_apps` and `install_apps` capabilities could cause a legitimate app installation to write files outside the intended app directory, into `$SPLUNK_HOME/etc/` and its subdirectories.<br><br>The vulnerability is caused by a path traversal in the app installation workflow, which does not restrict the installation path to the intended app directory.
Weakness Type
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-20297 has been classified to as a Directory traversal vulnerability or weakness.
Products Associated with CVE-2026-20297
stack.watch emails you whenever new vulnerabilities are published in Splunk or Splunk Cloud Platform. Just hit a watch button to start following.
Affected Versions
Splunk Enterprise:- Version 10.4 and below 10.4.1 is affected.
- Version 10.2 and below 10.2.5 is affected.
- Version 10.0 and below 10.0.8 is affected.
- Version 9.4 and below 9.4.13 is affected.
- Version 9.3 and below 9.3.14 is affected.
- Version 10.5.2605 and below 10.5.2605.0 is affected.
- Version 10.4.2604 and below 10.4.2604.6 is affected.
- Version 10.2.2510 and below 10.2.2510.18 is affected.
- Version 10.1.2507 and below 10.1.2507.24 is affected.