Impact
A low-privileged Splunk user lacking the fsh_manage capability can trigger remote code execution by selecting a federated search bundle. The flaw allows arbitrary code execution, granting the attacker access to all relevant data and threatening system integrity and availability. The issue arises because the Federated Search dispatch flow accepts caller-controlled bundle selection without enforcing the necessary capability check, which corresponds to the missing authorization weakness identified as CWE-862.
Affected Systems
Splunk Enterprise users running any version older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are affected. All other vendors or newer versions are not impacted. The vulnerability specifically targets the Splunk Enterprise platform's Federated Search functionality.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw can be triggered through a normal user interface or API by a low-privileged account, exploitation is likely feasible in environments where Federated Search is enabled and roles are not properly restricted. An attacker would need only local or network access to the Splunk server and could exploit the capability mismatch to execute code, potentially compromising confidentiality, integrity, and availability.
OpenCVE Enrichment