Impact
The flaw allows non‑admin users to submit crafted Splunk Web Manager Configuration (manager Extensible Markup Language) data that is processed without adequate input validation, a form of code injection (CWE‑94). Executing this payload gives the attacker full data access and the ability to alter the system’s integrity and availability.
Affected Systems
The vulnerability affects Splunk Enterprise installations running any of the following patched releases or earlier: versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Only the mentioned product and vendor are impacted; no other third‑party or partner software is listed.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score is not available. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves a legitimate user with a non‑admin role accessing the web interface to submit malicious configuration content; because the appropriate capability check is missing, an attacker can achieve code execution without elevated privileges. Given the high impact and the lack of built‑in mitigation, the risk is considered significant and a timelier response is advisable.
OpenCVE Enrichment