Impact
In affected Splunk Enterprise releases, the Dataset Explorer component does not validate or escape dataset names when assembling SPL searches, and it does not apply SPL safeguards to the resulting queries. An unauthenticated attacker can craft a malicious link that, when opened by an authenticated user, causes that user to run arbitrary SPL pipelines with the same privileges as the user. This flaw can allow the victim to access all data available to them, modify system behavior, or disrupt availability, but it does not provide direct code execution or privilege escalation beyond the victim's existing rights.
Affected Systems
All Splunk Enterprise installations running versions lower than 10.4.2, 10.2.6, 10.0.9, 9.4.14 or 9.3.14, provided Splunk Web is enabled. The vulnerability is not present in later patched releases and only affects instances where Dataset Explorer is exposed to users.
Risk and Exploitability
The CVSS score of 7.5 reflects a moderate to high severity, while the EPSS score is not available, indicating no current data on exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a social‑engineering step: an attacker must bait an authenticated user into clicking a crafted link. Since the attacker can only cause the victim to run queries with their own privileges, the impact is confined to the victim’s access scope. Nevertheless, the ability to execute arbitrary queries is a serious weakness that could enable data exfiltration or inadvertent system disruption.
OpenCVE Enrichment