Impact
In Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, or 9.4.14 an unauthenticated attacker can trigger an authenticated user to execute arbitrary Search Processing Language queries through the Event Type Builder. The crafted requests take advantage of a CSRF vulnerability that causes the builder to retain user supplied input and construct sample event searches. Successful exploitation can expose all data relevant to the authenticated user, including stored credentials, resulting in a significant information disclosure. This weakness falls under the CWE-943 vulnerability class, where application controlled input enables unintended functionality.
Affected Systems
The vulnerability is confined to Splunk Enterprise deployments with the Splunk Web component enabled. All versions older than 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected; newer releases incorporate the fix. The advisory does not specify any additional operating system or platform constraints, so any installation of the affected Splunk Enterprise releases that exposes the Event Type Builder is potentially impactable.
Risk and Exploitability
The CVSS base score of 5.9 indicates a moderate severity level. Because the exploit requires a phish‑induced request from an authenticated user, the actual risk is moderated by the need for social engineering. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. However, the presence of the CSRF vector and the potential to disclose sensitive data warrants timely remediation. The likely attack path is an attacker delivering a crafted request to an authentic user’s browser, causing the system to run the malicious SPL query on the user’s behalf.
OpenCVE Enrichment