Impact
An attacker with the ‘power’ role can embed malicious Search Processing Language (SPL) into a Table Editor dataset and share it. When a user with the ‘admin’ role opens the dataset in a browser, the stored SPL executes with admin privileges. This allows the attacker to read all data available to the admin and optionally modify a limited set of data. The vulnerability arises because the Table Editor does not enforce SPL safeguards for risky commands when preparing initial dataset data. The weakness is classified as CWE-863, indicating unauthorized use of privileged operations.
Affected Systems
Splunk Enterprise users running any of the following releases are affected: all versions older than 10.4.2, 10.2.6, 10.0.9, and 9.4.14. Only machines that have Splunk Web enabled and have users assigned to the ‘power’ or ‘admin’ roles are able to exploit the flaw.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. An attacker must first phish a power‑role user to submit a malicious dataset URL and then persuade an admin‑role user to open the dataset in the browser, triggering the execution. Once triggered, the attacker gains the full data view of the admin role and can tamper with a restricted subset of data. Because the attack requires both social engineering and a restricted set of privileged roles, the overall exploitability is moderate but not negligible.
OpenCVE Enrichment