Impact
The vulnerability allows a user lacking admin or power privileges to bypass Search Processing Language safeguards by injecting arbitrary SPL through a crafted Job Details dashboard link. The system fails to neutralize the caller‑supplied job identifier, enabling the injected SPL to run with the authenticated user’s credentials. This can expose all data the user is allowed to read and alter job state, thereby compromising the integrity of the system within that user’s authorization scope. The weakness is an input validation flaw, identified as CWE‑20.
Affected Systems
Affected product is Splunk Enterprise. Versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable. Users running these releases should inspect whether Splunk Web is enabled, as the issue is triggered via the Job Details dashboard.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity. Because an EPSS score is not available, the likelihood of exploitation is unknown from the advisory. The vulnerability is not listed in the CISA KEV catalog, yet it remains exploitable if a user can be tricked into opening a crafted link while Splunk Web is active. Official remediation requires upgrading to the patched releases; alternatively, disabling Splunk Web provides a workaround for environments that cannot upgrade immediately.
OpenCVE Enrichment