Impact
The flaw allows a user with a role other than admin or power to execute arbitrary code on a Splunk Enterprise instance by submitting crafted manager‑configuration values through the Web Manager Configuration interface. This code execution can read all private data, modify configurations, or disrupt availability, effectively compromising the confidentiality, integrity, and availability of the platform. The weakness is a classic code‑injection flaw (CWE‑94).
Affected Systems
The vulnerability is present in Splunk Enterprise installations running versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, specifically when the Splunk Web component and the Web Manager Configuration feature are enabled. Any instance that permits a non‑admin user to interact with Splunk Web is potentially affected. The remediation fixes are applied by upgrading to one of the fixed releases mentioned above.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be through the REST API underlying the Web Manager Configuration, which fails to enforce the necessary write‑permission checks. A knowledgeable attacker with web access and a low‑privilege account could supply a malicious configuration string to trigger code execution. Prompt application of the vendor patch or disabling Splunk Web is recommended to block exploitation.
OpenCVE Enrichment