Impact
In Splunk Enterprise, an unauthenticated user can register a crafted Deployment Server client identity that stores an arbitrary SPL pipeline. When an administrator later opens the Add Data forwarder workflow, the stored pipeline is executed with system privileges. This allows the attacker to read all indexed data, alter events, or disrupt the Splunk platform, compromising confidentiality, integrity, and availability. The weakness stems from unneutralized user input in a stored code context (CWE‑943).
Affected Systems
Splunk Enterprise installations running versions earlier than 10.4.1, 10.2.5, 10.0.9, or 9.4.14 are affected. The vulnerability is present in all 10.x and 9.x releases that precede these patch points, and only versions 10.4.2, 10.2.6, 10.0.9, 9.4.14 or newer contain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, signaling a serious risk, yet no EPSS score is reported. Because it can be triggered by any host that reaches the Splunk management port, the attack surface is wide for organizations that expose this port externally. Although the flaw is not in CISA's KEV, the combination of unauthenticated exploitation, system‑level privilege during execution, and the ability to read or modify all data means that the risk is high for exposed deployments. An adversary would first create a malicious Deployment Server client identity, register it with the Splunk deployment, and later rely on an administrator to open the Add Data forwarder workflow, which then runs the stored SPL payload with system privileges.
OpenCVE Enrichment