Splunk Enterprise Flaws Enable Credential Theft, Path Traversal, and SPL Abuse
ID: 0acab8c9-011b-58b3-8b91-81e78d95f7f4
STIX ID: report--0acab8c9-011b-58b3-8b91-81e78d95f7f4
Feed Name: Cyber Press
Splunk released patches for three vulnerabilities affecting Splunk Enterprise and Splunk Cloud: CVE-2026-20296 (high-severity CSRF in Deployment Server enabling forced SPL searches as splunk-system-user via crafted GET requests), CVE-2026-20297 (high-severity path traversal in the App Install REST endpoint allowing privileged users to write files under $SPLUNK_HOME/etc/), and CVE-2026-20298 (medium-severity information disclosure exposing encrypted password hashes via the storage/passwords endpoint). The advisory lists affected versions, remediation steps (upgrade to patched builds, a limits.conf change for the disclosure bug), and interim mitigations including disabling Splunk Web and reviewing role capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
