Impact
The vulnerability allows a non‑admin, non‑power user to create or modify scripted lookup definitions through raw configuration REST API endpoints. Because the endpoints do not enforce lookup capability checks, the privileged configuration of scripted lookups can be altered by users with lesser roles, potentially enabling malicious data processing or data exfiltration. The impact is limited to configuration changes; it does not grant arbitrary code execution or full system compromise. The weakness is an improper authorization flaw (CWE‑863).
Affected Systems
Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.10, and 9.4.15 are affected. Product: Splunk Enterprise (splunk.enterprise). Vendor: Splunk.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity. EPSS data is not available, so exploitation likelihood is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector is via the REST API accessed by authenticated users with standard user roles, exploiting the lack of authorization checks on raw configuration writes.
OpenCVE Enrichment