CVE-2023-32714: Splunk

High severity, CVSS 8.1. EPSS: 42.8% chance of exploitation in the next 30 days.

In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.

Affected products

  • Splunk Splunk: from 8.1.0, before 8.1.14 (fixed in 8.1.14); from 8.2.0, before 8.2.11 (fixed in 8.2.11); from 9.0.0, before 9.0.5 (fixed in 9.0.5)
  • Splunk Splunk App For Lookup File Editing: before 4.0.1 (fixed in 4.0.1)

Published 2023-06-01. Last modified 2026-06-17.