Impact
This vulnerability in Splunk Enterprise allows a user who does not have the admin or power role to upload a malicious knowledge bundle through the REST API. Because the endpoint does not enforce the high‑privilege capability edit_dist_peer, the distributed search component will accept the uploaded bundle and execute it on search peers. This can lead to arbitrary code execution, allowing an attacker to read all data, alter data, and potentially disrupt system availability. The weakness is a missing authorization check, aligning with CWE‑284.
Affected Systems
Splunk Enterprise installations with versions older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are affected. The flaw is present in the knowledge bundle upload API used by distributed search clusters. All roles that are not granted the admin or power capability are vulnerable when they can reach the endpoint.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV, but the lack of a KEV listing does not reduce the risk of exploitation in a targeted scenario. An attacker with legitimate or compromised non‑admin credentials could exploit the API to deploy a malicious bundle, giving them full system access. Because the attack vector relies on allowed API usage, an exploitation opportunity exists as long as an account without the required capability can access the Splunk REST interface.
OpenCVE Enrichment