Impact
Splunk Enterprise versions older than 10.4.2, 10.2.6, 10.0.9, and 9.4.14 allow an unauthenticated attacker to craft a link that an authenticated user may open in Analytics Workspace. When the link is opened, Splunk executes attacker‑controlled Search Processing Language (SPL) under the authenticated user’s permissions. This grants the attacker the same data access and operational privileges as the user, potentially exposing sensitive data and enabling undesired actions. The vulnerability stems from insufficient validation of search data when building queries.
Affected Systems
The affected product is Splunk Enterprise. Versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are impacted. Upgrading these installations to the specified patched releases removes the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact if exploited. The EPSS score is not available, so the current exploitation probability cannot be quantified accurately, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an unauthenticated attacker to phish an authenticated user into opening a malicious link; thus successful exploitation depends on social engineering attempts rather than automated exploitation.
OpenCVE Enrichment