Splunk Splunk Enterprise是美国Splunk公司的日志分析系统。 Splunk Enterprise存在路径遍历漏洞,该漏洞源于app安装工作流中存在路径遍历,未将安装路径限制在预期app目录内。以下版本受到影响:10.4.1之前版本、10.2.5之前版本、10.0.8之前版本、9.4.13之前版本、9.3.14之前版本、Splunk Cloud Platform 10.5.2605.0之前版本、10.4.2604.6之前版本、10.2.2510.18之前版本和10.1.2507.2
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk Cloud Platform | 10.5.2605< 10.5.2605.0 |
affected |
10.4.2604< 10.4.2604.6 |
affected | ||
10.2.2510< 10.2.2510.18 |
affected | ||
10.1.2507< 10.1.2507.24 |
affected | ||
| Splunk | Splunk Enterprise | 10.4< 10.4.1 |
affected |
10.2< 10.2.5 |
affected | ||
10.0< 10.0.8 |
affected | ||
9.4< 9.4.13 |
affected | ||
9.3< 9.3.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4 ~ 10.4.1 | - |
|
| Splunk | Splunk Cloud Platform | 10.5.2605 ~ 10.5.2605.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20296 | 8.3 HIGH | SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Serv |
| CVE-2026-20298 | 5.3 MEDIUM | Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Ent |
No comments yet