Impact
In Splunk Enterprise versions below the specified patches, a user who holds the schedule_search capability can trigger scheduled search alerts that execute arbitrary Search Processing Language commands with system-level privilege. This flaw enables the attacker to read all credentials stored in the credential store and potentially modify critical data, compromising system integrity and availability. The vulnerability stems from unsanitized handling of user‑specific alert action settings before the search scheduler runs the alert actions, reflecting an access control weakness described by CWE‑269.
Affected Systems
Splunk Enterprise users running any pre‑10.4.2 release (specifically versions 10.4.1 and earlier, 10.2.5 and earlier, 10.0.8 and earlier, and 9.4.13 and earlier) are affected. The remedial versions are 10.4.2, 10.2.6, 10.0.9, and 9.4.14 or later for each respective release line.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. No EPSS data is available, and the issue is not currently listed in the CISA KEV catalog. The attack vector is likely local or via privileged users who have the schedule_search capability; an attacker could configure or modify a scheduled search to execute arbitrary SPL, leading to privilege escalation within the Splunk environment.
OpenCVE Enrichment