Impact
A high‑privilege user who can manage a search head cluster can use the cluster member bundle REST API to drop files on any location writable by the Splunk Enterprise process. The API does not enforce the proper authorization boundary or validate the bundle path, enabling arbitrary file write that can lead to remote code execution. This weakness corresponds to CWE-284: Improper Access Control. Successful exploitation would give the attacker full access to all data in the deployment and could compromise the integrity and availability of the system.
Affected Systems
The vulnerability affects Splunk Enterprise versions below 10.4.2, including earlier 10.2.x and 10.0.x releases and 9.4.x prior to 9.4.14. Splunk Enterprise is the affected product, and the issue does not apply to releases 10.4.2 or newer.
Risk and Exploitability
The CVSS score of 6.0 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the REST API, requiring a user with a high‑privilege role that manages the search head cluster. If an attacker obtains such credentials, they can exploit the API to write files and trigger code execution, though the exploit requires the ability to access the Splunk API endpoints and privileges to perform file writes.
OpenCVE Enrichment