Impact
The vulnerability allows a user with the run_collect capability to specify index names that are not properly normalized, enabling writes to internal indexes that the role should not be able to access. This results in unauthorized data insertion, potentially compromising data integrity and leading to leakage of sensitive log information. The weakness is an input validation flaw classified as CWE-20.
Affected Systems
Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are impacted. Users running those versions on any platform are susceptible, regardless of the presence of system-level privileges.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available, suggesting no known high exploitation probability at present. The vulnerability is listed as not in the CISA KEV catalog. Exploitation requires an authenticated Splunk user with the run_collect capability; an attacker who can create or run a search can supply a crafted index name to overwrite or inject events into internal indexes beyond the role’s allowed scope. The attack vector is therefore limited to authenticated use, but the impact on internal data integrity could be significant for organizations relying on internal indexes for audit or monitoring purposes.
OpenCVE Enrichment