CVE-2026-20297: Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the editlocalapps and installapps capabilities could cause a legitimate app installation to write files outside the intended app directory, into $SPLUNKHOME/etc/ and its subdirectories.<br><br>The vulnerability is caused by a path traversal in the app installation workflow, which does not restrict the installation path to the intended app directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.1 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.5 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.8 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.13 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.3.14 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.5.2605.0 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.4.2604.6 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.18 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.24 - Compensating control
Restrict user roles so they do not grant both `edit_local_apps` and `install_apps` capabilities, since a user with these capabilities could exploit the app installation workflow to write outside the intended app directory.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20297?
The severity of CVE-2026-20297 is classified as high with a score of 7.2.
What is CVE-2026-20297?
CVE-2026-20297 is a vulnerability that allows path traversal through the 'explicit_appname' in the App Install REST Endpoint in affected versions of Splunk Enterprise and Splunk Cloud Platform.
How do I fix CVE-2026-20297?
To fix CVE-2026-20297, upgrade to Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, 9.4.13, or 9.3.14, or Splunk Cloud Platform versions 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, or 10.1.2507.24.
Which versions of Splunk are affected by CVE-2026-20297?
CVE-2026-20297 affects Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, as well as specific versions of Splunk Cloud Platform.
What capabilities are linked to CVE-2026-20297?
CVE-2026-20297 involves a user holding roles with the 'edit_local_apps' and 'install_apps' capabilities.