# CVE-2024-36985

## Summary

- **CVE ID:** CVE-2024-36985
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-687
- **Published:** Jul 1, 2024
- **Last Modified:** Mar 13, 2026

## Description

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.

## Affected Products

- Splunk — Splunk Enterprise (9.2)
- Splunk — Splunk Enterprise (9.1)
- Splunk — Splunk Enterprise (9.0)

## References

- [CNA](https://advisory.splunk.com/advisories/SVD-2024-0705)
- [CNA](https://research.splunk.com/application/8598f9de-bba8-42a4-8ef0-12e1adda4131)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 6.46%
- **EPSS Percentile:** 93.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._