Response playbooks, investigation guides, and Atomic Red Team tests are Pro-only. Upgrade to unlock the full detection package for CVE-2026-54617.

Unlock with Pro - from £29/user/mo
CVE-2026-54617 Splunk · SPL

Detect LaunchServer FileServerHandler Unauthenticated Path Traversal (CVE-2026-54617) in Splunk

Detects exploitation attempts against pro.gravit.launcher:launchserver-api's FileServerHandler, which is vulnerable to an unauthenticated path traversal (CWE-22) allowing arbitrary file read (CWE-200) and disclosure of sensitive data such as credentials or keys (CWE-522) in versions <= 5.7.11. Attackers send crafted HTTP requests containing traversal sequences (../, encoded variants, absolute paths) to the LaunchServer file-serving endpoint to read files outside the intended web root, including server configs, private keys, and auth databases.

MITRE ATT&CK

Tactic
Initial Access Collection

SPL Detection Query

Splunk (SPL)
spl
index=web_proxy OR index=iis (uri="*FileServerHandler*" OR url="*FileServerHandler*")
| regex uri="(\.\.%2f|\.\.%5c|\.\.\\\\|\.\.\/|%2e%2e%2f|%2e%2e\/|\.\.%c0%af)"
| stats count min(_time) as first_seen max(_time) as last_seen values(uri) as uris by src_ip, dest_ip, http_method
| where count > 0
| sort -count
critical severity medium confidence

Identifies path traversal attempts against the FileServerHandler endpoint in LaunchServer, associated with unauthenticated arbitrary file read exploitation.

Data Sources

Web Proxy LogsIIS LogsWeb Application Firewall

Required Sourcetypes

access_combinediisf5:bigip:asm

False Positives & Tuning

  • Automated vulnerability scanning tools performing authorized traversal checks
  • Encoded characters in legitimate launcher mod/asset filenames
  • Log ingestion misparsing of query strings

Other platforms for CVE-2026-54617


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Basic path traversal against FileServerHandler

    Expected signal: Web/proxy access log entry showing GET request to FileServerHandler with '../' sequences and response body containing /etc/passwd content or a 200 status.

  2. Test 2URL-encoded traversal against FileServerHandler

    Expected signal: Access log entry with percent-encoded traversal sequences in the request URI/query targeting FileServerHandler.

  3. Test 3Windows-style backslash traversal against FileServerHandler

    Expected signal: IIS/web log entry showing a request to FileServerHandler containing '..%5c' sequences and an unusual response size for win.ini content.

Unlock playbooks & atomic tests with Pro

Get the full detection package for CVE-2026-54617 — response playbook and atomic red team tests, plus investigation guidance and hunting queries.

df00tech Pro — £29/user/month

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections