Impact
Splunk Enterprise prior to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14 is vulnerable to SPL injection through the Monitoring Console. An unauthenticated attacker can trick an authenticated user into opening a specially crafted link. When the link is opened, the system executes attacker‑controlled SPL under that user’s permissions, allowing the attacker to read confidential data or perform any action available to that user. The weakness arises from insufficient validation of data used to build forwarder dashboard searches, corresponding to CWE-20 (Input Validation).
Affected Systems
The vulnerability affects Splunk Enterprise installations that have Splunk Web enabled. All releases before 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are impacted, including any instance that has not been upgraded to the specified fixed versions.
Risk and Exploitability
The CVSS score is 7.1, indicating a moderate to high severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, although the vulnerability still requires a phishing attack to lure an authenticated user to open a malicious link. Because the injected SPL runs with the user’s privileges, an adversary can potentially exfiltrate sensitive data or exercise any action the user is authorized to perform. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment