Impact
A low‑privileged user who is not an admin or power role can inject Structured Query Language commands into Splunk Enterprise by sending crafted data to the REST API, causing the system to execute attacker‑controlled text as part of a database query. This flaw is a classic input validation weakness and is classified as CWE-89.
Affected Systems
Splunk Enterprise versions earlier than 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS is not available, suggesting limited evidence of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is internal or external API access with non‑privileged credentials, which could allow an attacker to read or alter sensitive data stored in Splunk.
OpenCVE Enrichment