Impact
Monitoring Console in Splunk Enterprise does not validate data used to build dashboard searches, allowing an unauthenticated attacker to craft a link that, when opened by a user with the admin role, runs attacker‑controlled Search Processing Language (SPL) using that user's permissions. The injected SPL may expose data the user can access or modify lookup data, effectively granting the attacker escalation of privileges and potential data tampering or disclosure.
Affected Systems
Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected. The vulnerability applies to instances with Splunk Web enabled, as the crafted link is delivered through a web interface.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score is not available, making the exact exploitation probability unclear. The vulnerability is not listed in CISA's KEV catalog, suggesting it has not been widely observed in the wild. Exploitation requires social engineering; an unauthenticated attacker must trick an admin user into clicking the crafted link, which limits the attack surface but still presents a significant risk if successful.
OpenCVE Enrichment