Impact
An attacker who is not an administrator or power user can submit malicious SQL statements through the Data Orchestration jobs REST endpoint. The application constructs database queries from user-controlled job filter values without parameter protection, enabling the execution of arbitrary SQL. This allows the attacker to read all data stored in Data Orchestration, including jobs created by other users and connection credentials, effectively leaking confidential information.
Affected Systems
Affected product is Splunk Enterprise. Versions older than 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable. The issue arises in all Splunk deployments that enable Data Orchestration jobs endpoint with the PostgreSQL sidecar service enabled.
Risk and Exploitability
CVSS base score of 6.5 reflects moderate severity. No EPSS score is published, so the probability of exploitation cannot be quantified from the data, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires authenticated access to the REST API and the ability to send a crafted request to the Data Orchestration jobs endpoint. Once performed, the attacker can read data and credentials across the environment. The vulnerability is exploitable in any Splunk Enterprise installation that has Data Orchestration enabled and does not restrict the endpoint to privileged roles.
OpenCVE Enrichment