CVE-2023-40597: Splunk
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
Affected products
- Splunk Splunk: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only
- Splunk Splunk Cloud Platform: up to and including 9.0.2305.100
Published 2023-08-30. Last modified 2026-06-17.