Impact
Splunk Enterprise before the released patched versions allows a user without admin or power roles to supply a crafted search identifier to the REST API. Because the search identifier is not validated, an attacker can create a dispatch directory at an arbitrary location on the host, effectively writing metadata outside the intended path. This flaw enables the attacker to alter files or inject arbitrary data, thereby compromising the integrity of the system.
Affected Systems
All unsupported Splunk Enterprise releases that precede version 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected. The issue is limited to users who lack the admin or power roles, but any such user can trigger the path traversal via the search dispatch REST endpoint.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.7, indicating high severity. EPSS is not provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Attackers can exploit the flaw by sending a crafted request to the search dispatch REST API, which creates a directory in an arbitrary filesystem location, potentially modifying critical system or application files. The risk is high because the flaw does not require elevated privileges beyond non-admin roles and directly modifies host state.
OpenCVE Enrichment