Impact
Based on the description, it is inferred that the vulnerability allows a user with the power role to store a workflow action that contains attacker‑controlled SPL. When another authenticated user selects that action from the Event Actions menu, the stored SPL is executed with the permissions of the user who initiates the request. The injected SPL can read or alter data that the initiating user can normally access, effectively bypassing normal role‑based boundaries. This flaw is described as a Cross‑Site Request Forgery (CWE‑352) due to inadequate validation of workflow‑action URLs.
Affected Systems
Splunk Enterprise instances running any version earlier than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are affected. The issue exists only when the Splunk Web interface is enabled, as it is the channel through which the vulnerable workflow actions are triggered.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector requires the attacker to first create a malicious workflow action (by exploiting the power role) and then phish an authenticated user into selecting that action within their browser. This chain of events demonstrates that exploitation depends on user interaction and the presence of Splunk Web. The recommended resolution is to upgrade to a patched release (10.4.2 or later, 10.2.6 or later, 10.0.9 or later, or 9.4.14 or later) or, as an interim measure, disable Splunk Web so the vulnerable feature cannot be used.
OpenCVE Enrichment