logo

Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks

ID: 6f3f6551-2b74-50f8-9459-00c8d20d635a

STIX ID: report--6f3f6551-2b74-50f8-9459-00c8d20d635a

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Abinaya

...
...

Splunk released patches for three vulnerabilities in Splunk Enterprise and Cloud—CVE-2026-20296 (CVSS 8.3) allows arbitrary SPL execution via lack of CSRF validation when a user with list_deployment_server capability is phished; CVE-2026-20297 (CVSS 7.2) is a path traversal in the App Install REST endpoint that can write files outside the app directory; and CVE-2026-20298 (CVSS 5.3) can expose stored credential hashes via the /servicesNS/-/-/storage/passwords endpoint. Administrators should upgrade to the fixed releases or apply recommended mitigations (including masking encr_password and disabling Splunk Web where not needed).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.