CVE-2026-76337: Path Traversal through Splunk Web Static File Serving in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability is possible because Splunk Web does not restrict static file requests to the configured static directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.2 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.6 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.14
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote user can exploit it over the network. No credentials or user interaction are required.
What data can be exposed?
The issue allows reading JavaScript files located outside the configured Splunk Web static directory. The provided information does not indicate exposure of non-JavaScript files or modification capabilities.
Which Splunk Enterprise releases need remediation?
Versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected. Updating to the applicable listed release or later addresses the affected version range.