#VU126413 Insecure Temporary File in Splunk Enterprise - CVE-2026-20204
Published: April 17, 2026
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper handling and insufficient isolation of temporary files in the apptemp directory when uploading a malicious file to the $SPLUNK_HOME/var/run/splunk/apptemp directory. A remote user can upload a malicious file to execute arbitrary code.
The issue affects instances with Splunk Web enabled, and user interaction is required.