A path traversal vulnerability exists in Splunk Enterprise for Windows in versions prior to 9.2.2, 9.1.5, and 9.0.10. The /modules/messaging/ endpoint fails to properly sanitize user-supplied input, allowing an attacker to traverse directories and potentially access arbitrary files on the underlying Windows filesystem.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2024-36991, an unauthenticated path traversal in Splunk Enterprise on Windows. The repository contains only two files: a Python exploit script (CVE-2024-36991.py) and a README describing the vulnerability, affected versions, usage, and harvested file groups. The exploit is not part of a larger framework. Its main purpose is remote arbitrary file read against vulnerable Splunk web instances. The script presents an interactive picker that lets the operator choose categories of files to retrieve: credentials, configuration, logs/history, system fingerprinting files, and Splunk app directories. It then tests the supplied target URL, automatically determines the required traversal depth, confirms whether the host is vulnerable, and attempts to read each predefined file path. Retrieved content is printed to the console and stored locally in JSON format. The main exploit capability is data exfiltration rather than code execution. The targeted files include high-value Splunk secrets and credentials such as etc/passwd, splunk.secret, server.pem, authentication.conf, passwords.conf, and app-specific passwords.conf, along with server/web/input configs, operational and audit logs, session data, Windows hosts and win.ini, persistentstorage.db, and several Splunk app directories. This makes the tool useful for credential harvesting, configuration disclosure, environment fingerprinting, and follow-on access. Structurally, the script defines grouped target file lists, local logging helpers, output formatting, a vulnerability test routine, group dumping logic, and a main function that handles command-line input and interactive selection. The README aligns with the code and indicates the vulnerable endpoint is /modules/messaging/. Overall, this is a real, functional operational PoC for unauthenticated file disclosure on vulnerable Windows Splunk Enterprise deployments.
This repository contains a proof-of-concept (POC) exploit for CVE-2024-36991, a path traversal vulnerability in Splunk Enterprise versions 9.2.1, 9.1.4, and 9.0.9. The repository consists of four files: a Python exploit script (exploit.py), a README.md with usage and vulnerability details, a .gitignore, and a LICENSE file. The main exploit script, exploit.py, takes a target URL as input and attempts to retrieve sensitive files from the Splunk server by exploiting the path traversal flaw in the web interface. It specifically targets authentication configuration files and the Splunk secret file, which may contain credentials and other sensitive information. The exploit is network-based, requires the target to be accessible over HTTP(S), and is limited to Splunk instances configured with the en-US language. The code is a functional POC and does not include advanced payloads or post-exploitation features.
This repository contains a Python proof-of-concept exploit for CVE-2024-36991, a path traversal vulnerability in Splunk Enterprise (versions below 9.2.2, 9.1.5, and 9.0.10 for Windows). The exploit allows an unauthenticated attacker to read arbitrary files from the Splunk server's filesystem by sending specially crafted HTTP GET requests with path traversal sequences in the URL. The main script, 'CVE-2024-36991.py', takes user input for the target URL, file to read, and language, and can target both Splunk configuration files and system files (with an additional flag). The script first checks if the target is vulnerable by attempting to read '/etc/passwd', then proceeds to extract the contents of the specified file if the target is confirmed vulnerable. The README provides usage instructions and example commands. No additional payloads or post-exploitation actions are included; the exploit is focused solely on file read via path traversal.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-36991, a critical path traversal vulnerability in Splunk Enterprise for Windows (versions below 9.2.2, 9.1.5, and 9.0.10). The exploit consists of a Python script (exploit.py) and a README.md with usage instructions and vulnerability details. The script allows unauthenticated attackers to read arbitrary files from the Splunk server by exploiting a flaw in the web interface's handling of file paths. The user can select from five categories of files to target, including credentials, configuration files, logs, system files, and app scripts. The exploit works by issuing crafted HTTP requests (using curl) to the vulnerable endpoint, leveraging path traversal sequences to access sensitive files. The repository is structured simply, with the main exploit logic in exploit.py and comprehensive documentation in README.md. No detection or fake code is present; this is a functional PoC exploit for arbitrary file read via network attack vector.
This repository provides an operational exploit tool for CVE-2024-36991, a path traversal vulnerability affecting Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10. The main script, 'cvehunter.py', is a Python-based asynchronous tool that can scan single or multiple targets for the vulnerability. It attempts to exploit the flaw by sending a crafted HTTP GET request to the endpoint '/en-US/modules/messaging/C:../C:../C:../C:../C:../etc/passwd', aiming to read sensitive files (such as '/etc/passwd') from the server. The tool supports proxying, multi-threaded scanning, and output to a file. The repository also includes a README with usage instructions and a requirements.txt for dependencies. The exploit is not part of a framework and is a standalone operational tool capable of both detection and exploitation.
This repository contains a Python proof-of-concept (POC) exploit for CVE-2024-36991, a path traversal vulnerability affecting Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10. The exploit targets the Splunk Web interface and attempts to read the /etc/passwd file by sending a crafted HTTP GET request with a path traversal payload. The main script, CVE-2024-36991.py, supports both single-target and bulk scanning modes, reading targets from the command line or a file. It logs results to logs/scan.log and prints output to the console. The README provides usage instructions, requirements, and references. The exploit demonstrates the vulnerability by retrieving sensitive files from the server, confirming the presence of the flaw. No weaponized or post-exploitation payloads are included; the code is a POC for file read via path traversal.
This repository is a Python-based proof-of-concept exploit for CVE-2024-36991, a path traversal vulnerability in Splunk Enterprise on Windows (versions below 9.2.2, 9.1.5, and 9.0.10). The exploit is structured as a command-line tool with modular components: - The main entry point is `cve202436991/main.py`, which provides CLI options for scanning a single URL, reading a list of targets from a file, outputting results, configuring Telegram notifications, and opening a related blog post. - The core exploit logic is in `cve202436991/includes/scan.py`, which fetches a list of path traversal payloads from a remote GitHub file and attempts to access sensitive files on the target Splunk instance by constructing and sending HTTP GET requests. If a vulnerability is detected (e.g., the response contains sensitive markers like 'admin:'), it prints the vulnerable URL and optionally sends a notification via Telegram. - Supporting modules handle file reading/writing, configuration (including chatid for Telegram), and output formatting. - The tool is designed for use by penetration testers and bug bounty hunters to automate detection and exploitation of this specific vulnerability. Notable endpoints include the remote payload list, a Telegram notification API, and a local YAML config file. The exploit is a POC and does not provide weaponized or post-exploitation capabilities beyond file read and notification.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.