Impact
An attacker with a role that has the schedule_search capability can store a malicious script in a Splunk alert trigger condition field. When another user opens the resulting link, the script executes in that user's browser and can access all data available to that user. The flaw arises because Splunk Web inserts the alert threshold value into generated alert markup without escaping special characters, creating a stored Cross‑Site Scripting vulnerability (CWE‑79).
Affected Systems
Splunk Enterprise installations running any version older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 that have Splunk Web enabled are affected. The vulnerability is specific to roles that possess the schedule_search capability, so any user who can create such alerts could store the malicious script. All other users who view or click on the crafted alert link become victims.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate risk. EPSS data is not available, so the likelihood of exploitation cannot be quantified, but the attack requires the attacker to be authorized to create alerts and the victim must open the crafted link. The vulnerability is not listed in CISA’s KEV catalog, implying no publicly known widespread exploitation. Nevertheless, if exploited, the attacker can retrieve data from the victim's browser context, potentially compromising sensitive information. The official workaround—disabling Splunk Web—is a viable mitigation until a patch can be applied.
OpenCVE Enrichment