CVE-2023-40597: Splunk

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.

Affected products

  • Splunk Splunk: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only
  • Splunk Splunk Cloud Platform: up to and including 9.0.2305.100

Published 2023-08-30. Last modified 2026-06-17.