Impact
Splunk Enterprise versions below the specified patch levels allow a non‑admin or non‑power user to inject Search Processing Language (SPL) into saved‑search dispatch requests. This injection bypasses proper validation of caller‑supplied time values, permitting the attacker to execute arbitrary SPL and read or modify any data visible within the user’s scope. The vulnerability therefore undermines data confidentiality and system integrity in Splunk Enterprise.
Affected Systems
The affected product is Splunk Enterprise. Versions impacted include all releases earlier than 10.4.2, 10.2.6, 10.0.9, and 9.4.14. An individual with a role other than "admin" or "power" can exploit the flaw via the REST API.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS is not available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in CISA KEV. The most likely attack vector is through the public REST API endpoint that accepts time parameters for saved‑search dispatches, and the weakness is classified as CWE‑943.
OpenCVE Enrichment