Impact
An unauthenticated user with network access to the Patroni REST API in Splunk Enterprise can execute arbitrary operating‑system commands because the endpoint does not require authentication for critical configuration operations. This flaw is classified as CWE‑306, a missing‑authentication weakness, and allows an attacker to gain full control over the Splunk host, compromising confidentiality, integrity, and availability.
Affected Systems
Splunk Enterprise installations running any version below 10.4.3 or 10.2.7 are vulnerable; the vendor has fixed the issue in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 or later. Versions 10.0.x and 9.4.x are explicitly not affected. The vulnerability is relevant to search head cluster members that expose the Patroni REST API.
Risk and Exploitability
The CVSS score of 9.8 places this vulnerability in the critical range. The EPSS score is not available, and it is not listed in KEV, but the lack of authentication for a privileged API suggests a high likelihood of exploitation as soon as the REST endpoint is reachable. The likely attack vector is an unauthenticated request to the API from a host that has network connectivity to the Splunk cluster, either through an internal network or via a misconfigured firewall. Successful exploitation would allow the attacker to execute arbitrary commands on the host, leading to a full compromise.
OpenCVE Enrichment