Impact
An unauthenticated attacker can craft a Splunk Web URL that injects arbitrary Search Processing Language (SPL) commands into a logged‑in user's session. When the user opens the link, the injected SPL is executed using the authenticated user's permissions, allowing the attacker to read any data the user can access. This is a classic input injection flaw (CWE‑943) that can lead to arbitrary code or data execution on the Splunk platform.
Affected Systems
Splunk Enterprise deployments running versions earlier than 10.2.6, 10.0.9, or 9.4.14 are vulnerable. Versions 10.4 and later are not affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. Exploitation requires the attacker to phish the user into clicking a malicious link, so the likelihood of successful exploitation is limited by user awareness. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, because it can allow an attacker to run arbitrary SPL commands, the potential impact on confidentiality and integrity is significant if the user has elevated privileges.
OpenCVE Enrichment