Splunk has removed several security analytics from its Threat Research content library after the underlying vulnerabilities were patched in current releases, including detections tied to path traversal, SPL injection, CSRF, unauthorized admin account creation, and Analytics Workspace data exfiltration. The retired content covered CVE-2022-26889, CVE-2022-43566, CVE-2023-22942, and CVE-2023-22933, with detections aimed at spotting exploitation attempts in on-premises deployments through internal access logs, audit searches, and REST API queries.
The withdrawn detections had been designed to identify attacks such as crafted ../ traversal requests, abuse of the Splunk Secure Gateway kvstore_client endpoint, suspicious sid query activity in Analytics Workspace, and the presence of nonstandard administrative accounts that could indicate persistence or privilege escalation. Splunk said some analytics were deprecated because they were patched and no longer maintained, while at least one lookup file editing path traversal detection was removed because it did not accurately detect malicious activity and was ineffective against obfuscated requests; several notices also warned of false positives, disabled-by-default status, and limited usefulness without manual investigation.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-29, Splunk Threat Research removed the detection "Splunk Path Traversal In Splunk App For Lookup File Edit" from its content library. Splunk said the analytic was deprecated and did not accurately detect the malicious activity it was intended to find.
On 2026-05-14, Splunk Threat Research removed the hunting detection 'Splunk SG Information Disclosure for Low Privs User' from content library version 5.6.0 because the associated vulnerability, CVE-2024-45735, had been patched in current Splunk releases. The analytic had been designed to identify non-admin access to Splunk Secure Gateway KV Store deployment configuration and keys via the /splunkd/__raw/services/ssg/kvstore/ path.
On 2026-05-14, Splunk Threat Research removed the hunting detection 'Splunk RCE via Splunk Secure Gateway Splunk Mobile alerts feature' from content library version 5.6.0 because the associated vulnerability, CVE-2022-43567, had been patched in the latest Splunk release. The analytic had been designed to identify exploitation attempts against the Splunk Secure Gateway Mobile Alerts feature.
On 2026-05-14, Splunk Threat Research removed four detections from its content library because the associated vulnerabilities had been patched: "Path traversal SPL injection," "Splunk CSRF in the SSG kvstore Client Endpoint," "Splunk Data exfiltration from Analytics Workspace using sid query," and "Splunk list all nonstandard admin accounts." The removals were recorded in content library version 5.6.0.
Splunk released fixes for several vulnerabilities that later caused related detections to be retired, including CVE-2022-26889, CVE-2022-43566, CVE-2023-22933, and CVE-2023-22942. The references state these CVEs had been patched in the latest Splunk release.
Splunk published security advisory SVD-2023-0212 for the Splunk Secure Gateway kvstore_client endpoint vulnerability. The related detection content associates the issue with CVE-2023-22942.
Splunk published security advisory SVD-2022-0506 covering the vulnerability later referenced by the "Path traversal SPL injection" detection. The detection content maps the issue to CVE-2022-26889.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.