Impact
This vulnerability arises when a Splunk Enterprise user with the edit_user capability creates a native username ending with a period because the system fails to reject the trailing character before locating the user directory. The flaw allows distinct usernames to share per‑user configuration data, leading to unintended modifications of configuration files or user‑management actions that affect the wrong account. The result is loss of configuration integrity and potential privilege escalation if an attacker can influence another account’s settings. This issue is captured as CWE‑20, improper input validation.
Affected Systems
Splunk Enterprise deployments running any version prior to 10.4.3, 10.2.7, 10.0.10, or 9.4.15 that grant edit_user privileges through the REST API are susceptible. All roles possessing edit_user capability, including trusted administrators, are impacted.
Risk and Exploitability
The CVSS score of 4.1 indicates a moderate severity. An EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated REST API session with edit_user rights; no evidence indicates a network‑based exploitation path without such credentials. Damage is primarily limited to configuration integrity, but the ability to target another account’s configuration could facilitate privilege escalation, though the impact remains constrained compared to remote code execution.
OpenCVE Enrichment