PT-2026-33066 · Splunk · Splunk Enterprise+1
Published
2026-04-15
·
Updated
2026-05-19
·
CVE-2026-20204
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.2.1
Splunk Enterprise versions prior to 10.0.5
Splunk Enterprise versions prior to 9.4.10
Splunk Enterprise versions prior to 9.3.11
Splunk Cloud Platform versions prior to 10.4.2603.0
Splunk Cloud Platform versions prior to 10.3.2512.5
Splunk Cloud Platform versions prior to 10.2.2510.9
Splunk Cloud Platform versions prior to 10.1.2507.19
Splunk Cloud Platform versions prior to 10.0.2503.13
Splunk Cloud Platform versions prior to 9.3.2411.127
Description
A low-privileged user without
admin or power roles can achieve Remote Code Execution (RCE) by uploading a malicious file to the $SPLUNK HOME/var/run/splunk/apptemp directory. This is possible due to improper handling and insufficient isolation of temporary files within the apptemp directory.Recommendations
Update to version 10.2.1 or newer.
Update to version 10.0.5 or newer.
Update to version 9.4.10 or newer.
Update to version 9.3.11 or newer.
Update to version 10.4.2603.0 or newer.
Update to version 10.3.2512.5 or newer.
Update to version 10.2.2510.9 or newer.
Update to version 10.1.2507.19 or newer.
Update to version 10.0.2503.13 or newer.
Update to version 9.3.2411.127 or newer.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Cloud Platform
Splunk Enterprise