Splunk Enterprise carried an absolute path traversal vulnerability in the runshellscript command, tracked as CVE-2023-40597, that affected versions earlier than 8.2.12, 9.0.6, and 9.1.1. The flaw could allow arbitrary code execution from a separate disk, giving an attacker a path to take control of a Splunk instance and potentially expand access to sensitive log data or other connected systems.
Splunk Threat Research published a hunting analytic to spot exploitation attempts by reviewing internal splunk_python logs for runshellscript executions with suspicious path characteristics and a specific argument count, though the detection was later removed after patched releases became current. If exploited, attackers could use the resulting access to perform common post-compromise discovery activity such as enumerating files and directories to locate data for collection, exfiltration, or destructive actions including encryption or wiping.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the 'Splunk Absolute Path Traversal Using runshellscript' hunting analytic from its content library in version 5.6.0 because the associated CVEs had been patched. The entry notes the detection is no longer maintained or supported.
Splunk Enterprise releases 8.2.12, 9.0.6, and 9.1.1 addressed CVE-2023-40597, an absolute path traversal issue involving runshellscript that could enable arbitrary code execution. The detection content states the associated CVEs were already patched in current releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.