Impact
An authenticated user who does not have the edit_manager_xml capability can supply a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. When the user opens the affected Splunk Web Manager page, the system runs attacker‑controlled operating‑system commands under the Splunk Enterprise service account. The flaw is a classic code‑execution bug (CWE‑94), allowing an attacker to execute arbitrary commands on the host that runs Splunk Enterprise.
Affected Systems
Splunk Enterprise for all versions earlier than 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable. Only instances that run the Splunk Web component are impacted, as the exploitation path relies on the Web Manager page.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is classified as high severity. The EPSS score is not available, and the flaw is not yet listed in CISA KEV, but the fact that an authenticated user can trigger OS command execution means that any user with access to the Splunk interface presents a potential entry point. The attack vector requires the attacker to be authenticated and to modify the XML configuration, but does not need any special privilege beyond non‑edit_manager_xml access, making the exploit relatively easy to carry out in a compromised environment.
OpenCVE Enrichment