Impact
The vulnerability arises from an improper validation of the index name in the collect SPL command. An attacker who controls an SPL query via a role possessing the run_collect capability can inject arbitrary content into system‑level messages. This results in unauthorized modification of Splunk internal logs and messages. The weakness is a classic input validation flaw (CWE‑20).
Affected Systems
Affected systems are Splunk Enterprise installations where the collect command is available and the user’s role includes run_collect. Versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are vulnerable, regardless of the instance size or deployment type. Administrators should confirm whether any users or roles have run_collect, which is often granted to administrators or security analysts.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate overall risk. The vulnerability requires legitimate access to Splunk and a role with run_collect, so its exploitation vector is limited to internal or compromised accounts. EPSS is unavailable, and the issue is not listed in KEV, suggesting lower attack prevalence. Nevertheless, attackers could leverage this to tamper with system messages, potentially hiding malicious activity or confusing audit trails. Immediate remediation by patching is recommended to eliminate the risk.
OpenCVE Enrichment