Impact
The vulnerability is a SPL injection flaw that allows an unauthenticated attacker to craft a URL that, when opened by an admin-level user, causes the system to run arbitrary SPL commands with that user's privileges. This can expose sensitive data, alter search results, or modify lookup data, and is caused by the Secure Gateway app not properly neutralizing caller‑supplied values in dashboard searches.
Affected Systems
Splunk Enterprise versions older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 and Splunk Secure Gateway versions prior to 3.10.9, 3.9.23, or 3.8.70 are affected. In particular, users of Splunk Enterprise and its Secure Gateway app who have admin or sc_admin roles are vulnerable.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. The EPSS score is not available, but the vulnerability still represents a potential risk because an attacker can coerce an admin to open a malicious URL. Although not listed in the CISA KEV catalog, an exploit would allow an attacker to execute arbitrary SPL commands, exposing or manipulating all data accessible to the targeted user. The vulnerability requires user interaction, making it less likely to be automated but still serious if phishing succeeds.
OpenCVE Enrichment