Impact
Splunk Enterprise versions earlier than 10.4.1, 10.2.6, 10.0.9, and 9.4.14 allow a user with the "power" role to embed attacker‑controlled SPL in a dashboard. When another authenticated user exports that dashboard to PDF, the system runs the injected SPL using the exporting user's permissions. The result is that an attacker can read or alter any data the exporting user is authorized to see, effectively bypassing normal access control boundaries. This flaw is a typical command injection vulnerability (CWE‑77) that does not directly affect the host OS but can compromise the integrity and confidentiality of Splunk data.
Affected Systems
The affected product is Splunk Enterprise. All releases prior to 10.4.1, 10.2.6, 10.0.9, and 9.4.14 are vulnerable. Upgrading to at least 10.4.2, 10.2.6, 10.0.9, or 9.4.14 (and later) removes the flaw.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate to high risk. Exploitation requires a legitimate authenticated session and a phishing‑style trick to have the target user initiate a PDF export. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploits at present. Nevertheless, the potential for data exfiltration or tampering warrants prompt attention.
OpenCVE Enrichment