Impact
This vulnerability occurs when a user who does not hold the admin or power Splunk roles submits a crafted knowledge bundle delta. The delta causes Splunk Enterprise to delete files beyond the intended staging directory because removal paths are not restricted and the endpoint does not enforce the authorization boundary. The result is deletion of arbitrary files that the Splunk cluster manager can access, compromising system integrity and potentially disrupting service availability.
Affected Systems
Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to this path traversal issue.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by constructing a custom knowledge bundle delta and posting it to the cluster manager; the attack requires at least a normal user account, so compromised or weak accounts increase the risk. This vulnerability does not enable remote code execution, but the ability to delete arbitrary files represents a significant impact on integrity and could lead to downtime.
OpenCVE Enrichment