Impact
An unauthenticated user can inject arbitrary Search Processing Language into nearby-event search requests because Splunk Web fails to escape user‑supplied values when constructing the SPL. The injected SPL is executed by embedded report access without the expected authorization check, giving the attacker the ability to run any search that may expose sensitive data or invoke system commands. This vulnerability is a classic CWE-77 case of command injection via an insufficiently‑validated input.
Affected Systems
The flaw exists in Splunk Enterprise deployments running any version older than 10.4.2, 10.2.6, 10.0.9 or 9.4.14, provided Splunk Web is enabled. Only instances that expose the web interface can be targeted; turning off Splunk Web removes the vulnerable code path.
Risk and Exploitability
With a CVSS score of 7.3 the vulnerability is considered high severity. Although there is no EPSS score, the lack of an authentication requirement and the fact that the flaw resides in a publicly accessible web component raises the likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, but it remains dangerous for any exposed Splunk Web instance.
OpenCVE Enrichment