CVE-2024-36991
HIGH 7.5EPSS 13.0%
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 13.01% chance of exploitation in the next 30 days, 96th percentile
- Nuclei
- high
- Published
- 2024-07-01
- Updated
- 2025-02-28
Proof-of-concept exploits (13)
- Cappricio-Securities/CVE-2024-369913★ · 2024-07-10
- Mr-xn/CVE-2024-369919★ · 2024-07-06
- MrR0b0t19/SplunkVuln1★ · 2024-07-11
- TcchSquad/CVE-2024-36991-Tool2★ · 2025-10-30
- TheStingR/CVE-2024-36991-Tool2★ · 2025-10-30
- Zin0D/CVE-2024-369913★ · 2026-06-21
- bigb0x/CVE-2024-36991127★ · 2024-07-12
- gunzf0x/CVE-2024-369914★ · 2025-03-31
- jaytiwari05/CVE-2024-369919★ · 2025-03-30
- sardine-web/CVE-2024-369911★ · 2024-07-06
- th3gokul/CVE-2024-369912★ · 2024-07-06
- 0xFZin/CVE-2024-36991
- jhurtadomi/CVE-2024-36991-Splunk